Gyazo breach exposed 23.6m records and image links
Helpfeel says a flaw in Gyazo's image upload server let an attacker run commands and take 23.62 million user records plus metadata for around 490 million images.

Gyazo has confirmed a data breach in which an attacker broke into the screenshot service's image upload server and took 23.62 million user records along with metadata for roughly 490 million images. Helpfeel, the Japanese company behind Gyazo, published its findings on 16 September 2026, five days after the intrusion began.
What did the attacker actually take?
The 23.62 million user records include names or nicknames, email addresses, password hashes, Gyazo user and device identifiers, login session IDs, X integration tokens, the email address linked to a Google single sign-on account, profile information, language preference, registration and last-login times, subscription plan, billing status and usage statistics. Which fields are present varies by account, and the total includes anonymous accounts with no registered email address at all. Helpfeel says no payment information, including credit card numbers, was disclosed.
What about the images themselves?
Metadata for approximately 490 million images was taken, mostly for images uploaded in or before January 2019, which is about 14.4% of all image-related data. That metadata includes the image ID used to build a Gyazo image URL, the source IP address used to upload, the browser user agent, EXIF location data where the image carried it, text pulled from the image by OCR, the image title, the source URL, and the hashed passphrase protecting private images. A further 2.4 million images had their metadata retrieved using what Helpfeel calls specific filtering criteria. The company says it has not confirmed any loss of image data itself.
Could private screenshots have been seen?
Possibly, and Helpfeel says so directly. The company has confirmed that the attacker obtained a list identifying private images and that it cannot rule out the possibility that some private images were viewed. The image ID in the stolen metadata is exactly the material needed to construct a working link to a capture, and Gyazo has temporarily disabled viewing of some images to limit the damage. This is the part of the incident that matters most: on a default Gyazo capture, the link is the only protection, and a share of the material that generates those links has leaked.
How did Helpfeel respond?
The intrusion began on 11 September 2026, when a third party exploited a vulnerability in the image upload server to execute arbitrary commands. Helpfeel detected suspicious activity that evening, and by the early hours of 12 September it had blocked the access routes used and severed the attacker's connections, remediating the vulnerability. On 14 September it confirmed that information had been disclosed and began suspending image delivery while it assessed the scope. Helpfeel says it reported the incident to Japan's Personal Information Protection Commission on 15 September. Its other products, Helpfeel and Cosense, use different architecture and no unauthorised disclosure has been confirmed there, although images embedded in them through Gyazo are currently unavailable.
What should Gyazo users do now?
Change the Gyazo password, and change it anywhere else it was reused, because password hashes were taken. Helpfeel plans to email registered users it identifies as affected and will notify anonymous account holders through the Gyazo web interface, since it has no address to write to. Anyone who connected a Gyazo account to X or to Google sign-in should review those connections, and the ordinary phishing caution applies with more force than usual: a breach notice this detailed is ideal material for a convincing follow-up email.
What is still unknown?
A great deal. Helpfeel has not said what the vulnerability in the upload server was, whether it has been assigned a CVE, or whether any other service running the same code is exposed. It has not established how many individual people the 23.62 million records actually represent, which matters because that figure counts accounts rather than humans. It has not listed which session IDs it invalidated or which images had viewing disabled. With session identifiers, device IDs and source IP addresses all in the same leak, the practical risk to anonymous users is still being worked out. Helpfeel says its investigation continues and that it will publish updates.
Our opinion
Gyazo's real problem is structural, and it is worth saying plainly. The default capture is private because the link is unguessable, which turns every screenshot into a secret that travels by link into group chats, support tickets and shared documents, while the metadata behind it keeps a permanent record of where it came from. Leak the identifier that builds those links alongside source IP addresses and EXIF coordinates, and the images do not have to be downloaded for the protection to fail: the attacker walked away with a map, not merely a pile of pictures. Helpfeel's response has been fast and its notice unusually specific, which counts for something, but the two questions left open matter more than the headline number. What was the flaw, and how many named people does 23.62 million accounts really mean? Telling users to change passwords without being able to answer the second one leaves every affected person guessing at their own exposure. The wider lesson is the old one about screenshots: they are the most context-rich files most of us own, we paste them into systems nobody audits, and the thing standing between them and the internet is still a link.
- Helpfeel confirmed the Gyazo breach in a notice published on 16 September 2026
- An attacker exploited a vulnerability in Gyazo's image upload server on 11 September 2026 to execute arbitrary commands
- Approximately 23.62 million user records were disclosed, including password hashes, session IDs and email addresses
- Metadata for approximately 490 million images was taken, mainly from images uploaded in or before January 2019
- The metadata includes the image ID used to build Gyazo image URLs and the hashed passphrase for private images
- Helpfeel cannot rule out that some private images were viewed
- No payment information, including credit card numbers, was disclosed
- Helpfeel blocked the access routes by 12 September and reported the incident to Japan's PIPC on 15 September
- The vulnerability itself has not been described and no CVE has been cited
- Helpfeel and Cosense were not affected, though some Gyazo images embedded in them are unavailable