
Helpfeel has disclosed a major data breach affecting its Gyazo image-sharing service, after an attacker exploited a vulnerability in an upload server to execute arbitrary commands and access backend systems.
The incident exposed approximately 23.62 million user-related records and metadata associated with roughly 490 million images, including information that could potentially be used to reconstruct image URLs and access uploaded content.
Helpfeel said the unauthorized access occurred on September 11, 2026, with suspicious activity detected later that evening. The company began investigating and, by the early hours of September 12, had blocked the identified access routes, terminated the attacker’s connections, and remediated the exploited vulnerability.
Further investigation determined that the attacker accessed Gyazo’s database and extracted user information as well as image metadata. Helpfeel confirmed the data theft on September 14 and subsequently suspended some image delivery while implementing additional safeguards.
Gyazo is a screenshot and media-sharing platform operated by Kyoto-based Helpfeel Inc. The service allows users to quickly capture and upload screenshots, GIFs, and videos, generating links that can be shared or embedded elsewhere. Helpfeel also operates its namesake knowledge-management service and Cosense, although the company says those systems use different architectures and have not shown evidence of compromise.
The exposed user records may contain names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription and billing status, login timestamps, and usage statistics.
Helpfeel stressed that the dataset includes anonymous accounts and that 23.62 million records do not necessarily represent the same number of identifiable individuals. No credit card numbers or other payment-method information were exposed.
The attacker also obtained approximately 490 million metadata records, primarily covering images registered in or before January 2019, representing about 14.4% of Gyazo's image-related data. Metadata for another 2.4 million images was separately retrieved using specific filtering criteria.
The exposed metadata may include image IDs, upload IP addresses, User-Agent strings, EXIF location information, OCR-extracted text, image titles, source URLs, and hashed passphrases used for private images.
Of particular concern, image IDs can be used to construct Gyazo URLs. Helpfeel warned that the stolen information could therefore enable unauthorized access to corresponding images and temporarily disabled viewing of some content as a precaution.
The attacker also obtained a list identifying private images. Helpfeel said it cannot currently rule out that some private images were viewed.
The company has invalidated or restricted affected authentication-related information and reported the incident to Japan's Personal Information Protection Commission on September 15. External forensic specialists are continuing to investigate the breach.
Gyazo users should change their passwords immediately, particularly if the same or similar credentials are used elsewhere. Users should also be cautious of phishing emails or messages that could exploit exposed profile, account, or image-related information, and should review potentially sensitive Gyazo uploads that may have been affected.







Leave a Reply