www.securityweek.com 18 Sept 2026, 11:38 UTC

Gyazo Hack Exposes 23.6 Million User Records and Image Data

Gyazo Hack Exposes 23.6 Million User Records and Image Data
CyberSIXT Evidence Panel Source marked as original reporting

JAPANESE software company Helpfeel has warned Gyazo users that hackers accessed the image-sharing service’s servers. The attacker exploited a vulnerability in Gyazo’s image-upload server on 11 September, allowing malicious commands to be executed, according to Helpfeel. The company removed the attacker the following day, but the intruder had accessed a database containing approximately 23.62 million user records.

The exposed information may include names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics and billing information. Helpfeel said payment-card data was not compromised. The total includes anonymous accounts without a registered email address, and the company is still determining how many individuals had personal information disclosed.

The breach also involved roughly 490 million image-metadata records, some of which could help attackers reconstruct or access URLs linked to uploaded images. A list of private images was accessed, although Helpfeel has not disclosed its size.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline