Helpfeel Confirms Leak of 23.62 Million Gyazo Records

Helpfeel confirmed the unauthorized exposure of millions of records from Gyazo after a vulnerability in the image upload server was exploited.

Helpfeel, the company that operates the service, confirmed the Gyazo breach. On September 11, 2026, an attacker exploited a vulnerability in the image upload server, gained unauthorized access and ran arbitrary commands on it. The company subsequently confirmed the unauthorized exposure of approximately 23.62 million user-related records.

This number does not represent the number of unique affected people. The records also include anonymous accounts, and one user may have multiple records.

Gyazo breach includes accounts and image metadata

According to Helpfeel, the exposed records may contain email addresses, hashed passwords, device and session identifiers, profile data and subscription information. For users with linked sign-ins, an X service token or Google SSO email may also have been affected.

The incident also includes metadata for approximately 490 million images, most of which were uploaded by January 2019. In addition, the company reported about 2.4 million other metadata records obtained under separate, narrower conditions.

The metadata may contain information that can be used to construct image URLs. According to the company, the attacker obtained a list of private files, so Helpfeel cannot rule out that some private images were viewed. However, there is no public confirmation that private images were actually exfiltrated.

The company also said that payment card numbers were not exposed.

Server remediation and user notifications

Helpfeel fixed the vulnerability, blocked the identified access paths and terminated unauthorized connections by the early morning of September 12. On September 15, it notified Japan’s Personal Information Protection Commission and began gradually contacting users who may have been affected by the incident.

In a notice dated September 18, the company added that it had found no evidence of a data breach or traces of an attack in the separately operated Helpfeel and Cosense systems.

Risks posed by the incident

The exposure of email addresses and password hashes primarily creates risks of targeted phishing messages and account takeover attempts where people reused the same password. Image metadata may contain sensitive information, such as IP addresses, EXIF location data or text recognized using OCR technology.

Helpfeel recommended that users change their passwords. This is especially important if a Gyazo password was also used with other services. There is currently no public confirmation that the leaked password hashes or other data have already been used in subsequent attacks.

Technical vulnerability details are missing

The operator has not disclosed the type of flaw exploited or its CVE identifier. The attacker’s identity is also unknown. The investigation is continuing, and the results of an external forensic review, any adjustment to the scope of the incident and further notifications to users or regulators will be important.

It also remains an open question whether Helpfeel will later confirm the viewing or theft of private images and whether evidence will emerge of data being abused in phishing or credential-stuffing campaigns.

Sources

Verified and updated: 09/19/2026 06:23

Sharing