securityaffairs.com 18 Sept 2026, 17:10 UTC

Gyazo Hack Exposes 23.6 Million User Records and Image Data

Gyazo Hack Exposes 23.6 Million User Records and Image Data
CyberSIXT Evidence Panel Source marked as original reporting

HELPFEEL , the Japanese company behind the Gyazo screenshot and screen-recording service, said an attacker accessed its servers on 11 September 2026 by exploiting a vulnerability in an image-upload server. The attacker was blocked the following day, but had already run malicious commands and accessed a database containing approximately 23.62 million user records.

The exposed information may include names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription and billing status, usage statistics and registration and last-login dates. Anonymous accounts without registered email addresses were also included. Helpfeel said payment card information, including credit card numbers, was not exposed.

The company also reported exposure of metadata relating to about 490 million images, mainly those uploaded in or before January 2019, plus metadata from 2.4 million other images accessed through specific searches. This may include image IDs, upload IP addresses, User-Agent data, EXIF location information, OCR text, titles, source URLs, hashed passphrases and other metadata. Helpfeel said the data could potentially help reconstruct Gyazo URLs and access images without authorisation.

It confirmed that a list of private images was obtained, but has not confirmed that image files were stolen or that private images were viewed. The investigation remains ongoing; Helpfeel has blocked the access routes, fixed the exploited vulnerability and plans to notify affected users by email or through Gyazo. It recommends changing Gyazo passwords, particularly reused ones, and watching for suspicious messages.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline