Gyazo Upload Server Breach Exposes 23.6 Million Accounts and Metadata for 490 Million Images
An attacker exploited a flaw in the image upload server of Helpfeel's Gyazo screenshot service, taking 23.62 million user records and 490 million image metadata records that could be used to open uploaded images. Helpfeel disclosed the breach on September 16, 2026.
VaultTools · September 23, 2026
Photo on Unsplash
Table of Contents
- What happened
- What was exposed
- How it happened
- The disclosure timeline
- Why this matters for browser-based file tools
- Sources
What Happened
Helpfeel, the Japanese company behind the Gyazo screenshot and image-sharing service, disclosed on September 16, 2026 that an attacker broke into its systems and took about 23.62 million user records plus roughly 490 million image metadata records. According to Helpfeel’s notice, the metadata “could be used by a third party to access and view the corresponding images without authorization.”
SecurityWeek reported that the affected records “include records for anonymous accounts with no registered email address,” meaning people who uploaded screenshots without ever signing up are also part of the dataset.
What Was Exposed
According to Helpfeel, the user records may include names, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile information, subscription plan and billing status. The company stated that “no payment information, including credit card numbers, was disclosed without authorization.”
The image metadata is the more unusual part. It covers images registered up to January 2019 (about 14.4% of Gyazo’s image data), plus around 2.4 million further records the attacker pulled with specific filters. Per Helpfeel, it includes image IDs, uploader IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs and a “hashed passphrase for private images.”
The Hacker News explained why the image IDs matter: Gyazo links work on the principle that “anyone who has the link can see it,” and the leaked IDs are “the part of the link that makes it unguessable.” Helpfeel said it found no evidence that the image files themselves were taken, but “cannot rule out the possibility that the third party may have viewed some private images.”
How It Happened
Helpfeel’s notice states that “a third party exploited a vulnerability in Gyazo’s image upload server to gain unauthorized access to our systems and execute arbitrary commands.” From there, the attacker reached Gyazo’s database. Helpfeel has not publicly identified the vulnerability. The company said its other products, Helpfeel and Cosense, were not compromised.
The Disclosure Timeline
- September 11, 2026 — suspicious activity detected in the evening, Japan time
- September 12 — access routes blocked, attacker connections cut, vulnerability fixed
- September 14 — unauthorized disclosure confirmed, image delivery suspended
- September 15 — delivery resumed for new uploads, report filed with Japan’s Personal Information Protection Commission
- September 16 — public notice published
Helpfeel asked all Gyazo users to change their password, and to change it on any other service where they reused it.
Why This Matters for Browser-Based File Tools
The entry point was the upload server itself: the component whose job is to receive files from users. Once it was compromised, the attacker gained the index to years of uploaded screenshots, along with OCR text extracted from them and the location data embedded in their EXIF tags. Screenshots routinely capture things never meant to be public, from chat messages to invoices and dashboards.
Some workflows genuinely require hosting, and sharing a link to an image is one of them. But many file tasks (resizing, converting, compressing, stripping EXIF data before sharing) do not. When those run in the browser, the file never passes through an upload server, no OCR text or location metadata is indexed on someone else’s database, and there is no years-old archive left behind to be breached later.
Sources
- Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo (Helpfeel, September 16, 2026)
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records (The Hacker News, September 17, 2026)
- 23 Million User Records Compromised in Gyazo Data Breach (SecurityWeek, September 18, 2026)
- Hackers exploit Gyazo server flaw to steal 23.6 million user records (Help Net Security, September 21, 2026)