Gyazo's Breach Leaked 23 Million Accounts and 490 Million Image Links Anyone Can Open
Helpfeel confirmed attackers exploited Gyazo's image-upload server and took about 23.62 million user records plus 490 million image metadata records, including image IDs that rebuild public links. Exposed fields include OCR text, EXIF location, and X integration tokens. Credit cards were not exposed.

The Hacker News (Swati Khandelwal, 17 September 2026) and BleepingComputer (Bill Toulas, 18 September 2026) reported Helpfeel's disclosure that attackers exploited a vulnerability in Gyazo's image-upload server, ran arbitrary commands, and accessed the database.
This is a confirmed company disclosure of a completed data breach. It is not a CVE-first advisory, not a claim that payment cards leaked, and not proof that every private image was opened.
Gyazo is Helpfeel's screenshot and screen-recording cloud, popular in gaming. The company claims about 23 million users and 3.1 billion media items.
About 23.62 million user records were exposed, including anonymous accounts with no registered email. Fields can include name or nickname, email, password hash, user, device, and session IDs, an X (Twitter) integration token if the account was connected, a Google SSO email if connected, profile, language, registration and last login times, subscription plan, billing status with no credit card numbers, and usage statistics. Helpfeel is still working out how many identified people sit behind those records.
About 490 million image metadata records were also taken, mostly for images from January 2019 or earlier, about 14.4 percent of image-related data. A further 2.4 million records were pulled through a separate filter. Helpfeel has not said whether those sets overlap.
The dump included OCR text extracted from captures, EXIF location if present, and X integration tokens for connected accounts, plus image IDs that rebuild public URLs, upload IP, User-Agent, title, source URL, and hashed passphrases for private images. Those IDs can be used to view images without permission. Helpfeel temporarily disabled viewing of some affected images.
The attacker also obtained a list identifying private images. Helpfeel said it cannot rule out that some private images were viewed. The company has found no evidence image data was deleted. Helpfeel and Cosense run on separate systems, and no exposure was found there.
Helpfeel noticed suspicious activity on the evening of 11 September, Japan time, then blocked the access routes and fixed the vulnerability in the early hours of 12 September. It confirmed exposure on 14 September, reported the incident to Japan's Personal Information Protection Commission on 15 September, and published the notice on 16 September. Earlier public notices framed loading failures as maintenance or emergency maintenance.
No attacker has been named. Credit cards were not in the dump. A record count that includes anonymous accounts is not the same as 23.62 million identified people.
Related account and token tape includes Plugin4Shell in AI coding agents, Hacktron's path into OpenAI source code, and Revolut's fake government-request breach.
If you have a Gyazo account, including an anonymous one, change that password and any reused password today, revoke an X connection if the account had one, and treat old image IDs as public until Helpfeel says those links are dead.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free