Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
Gyazo Data Breach (TL-2026-2566) is a high-severity data breach, first published 2026-09-18. It has no confirmed attribution, affects Helpfeel Inc. Gyazo (image upload server / image-sharing platform), maps to 10 MITRE ATT&CK techniques (T1059, T1078, T1110.004), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2566
- Threat ID
- TL-2026-2566
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-18
- Last reviewed
- 2026-09-18
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, softwaresaas, mediaandpublishing
- Target regions
- japan, Global
- Detection rules
- 9
- Indicators of compromise
- 9
Helpfeel Inc., the Kyoto-based operator of the Gyazo image-sharing/screenshot service, disclosed on 2026-09-16 that a third party exploited a vulnerability in Gyazo's image upload server on 2026-09-11 to gain unauthorized access and execute arbitrary commands, ultimately reaching Gyazo's database. Approximately 23.62 million user records (names, emails, password hashes, device/session IDs, X/Twitter and Google SSO tokens, billing status) and roughly 492.4 million image metadata records (image IDs, IPs, EXIF location, OCR text, hashed private-image passphrases) were exposed; payment card data was not affected.
How Gyazo Data Breach works
On the evening of September 11, 2026 (Japan time), an unauthorized third party exploited a vulnerability in the image upload server operated by Helpfeel Inc. for its Gyazo image-sharing and screenshot service, gaining unauthorized access to Helpfeel's systems and executing arbitrary commands. Multiple secondary outlets (The Hacker News, RodTrent's roundup) characterize this as a critical server-side flaw in the upload component, consistent with unsafe file-handling or input-validation weaknesses, though Helpfeel itself has not disclosed the specific vulnerability class or CVE. Helpfeel detected the suspicious activity the same evening and began an incident response; by the early hours of September 12 the company had blocked the identified access routes, terminated the attacker's active connections, and patched the exploited vulnerability — a containment window of roughly 24 hours from detection to remediation.
Helpfeel's own notice states that its other products, Helpfeel (the help-center/FAQ SaaS) and Cosense (formerly Scrapbox), run on "different system architectures" and showed no confirmed unauthorized disclosure, indicating the compromise was scoped to the Gyazo image upload server and its backing database rather than Helpfeel's broader corporate environment.
On September 14, Helpfeel confirmed that data had been unauthorizedly disclosed and suspended image delivery as a precaution. On September 15, the company implemented additional protective measures — invalidating and restricting existing authentication/session tokens — and submitted a breach report to Japan's Personal Information Protection Commission (PPC), as required under Japan's Act on the Protection of Personal Information. On September 16, Helpfeel published a public notice and apology disclosing the scope of the incident and urging all Gyazo users to change their password, and to change it on any other service where the same or a similar password was reused.
The exposed user dataset comprises approximately 23.62 million records, including accounts with no registered email (anonymous accounts). Fields include names, email addresses, password hash values, user IDs, device IDs, login session IDs, X (formerly Twitter) integration tokens, Google SSO linkage emails, profile/language preferences, registration and login dates, subscription plan, and billing status; Helpfeel states payment card numbers were not compromised. The Hacker News additionally reported that whether the exposed login session IDs remain cryptographically valid — and whether Gyazo's new-IP login verification would block their reuse — was not clearly resolved by Helpfeel's disclosure at the time of reporting, leaving open a residual account-takeover/session-hijack risk pending full confirmation of token invalidation.
Separately, roughly 490 million image metadata records tied to images registered before January 2019, plus an additional 2.4 million records retrieved via what Helpfeel described as "specific filtering criteria," were exposed. This metadata includes the 32-character image IDs that compose Gyazo share URLs (Gyazo markets these as effectively "unguessable," using ID secrecy as the primary access control for default-privacy images), uploader IP addresses and User-Agent strings, EXIF geolocation data embedded in images, OCR text Gyazo extracts from paid users' captures (which Gyazo's own documentation states only the uploader can see), image titles/source URLs, and hashed passphrases protecting private images. Because the image IDs themselves were exposed, the sole access-control mechanism protecting many default-privacy captures has been defeated, making URL reconstruction and unauthorized viewing of historical images feasible without any enumeration or brute-forcing — the leaked IDs are themselves the secret. Reporting also indicates the attacker obtained a list specifically identifying which images were flagged private, and Helpfeel has stated it "cannot rule out the possibility that the third party may have viewed some private images." Helpfeel has temporarily disabled delivery of some existing (unnamed subset of) images and resumed delivery only for newly uploaded content while the investigation continues; because the image ID is the sole secret, deletion — not rotation — is the only mitigation available for already-exposed links. An external forensics firm is conducting an ongoing investigation, with Helpfeel committing to publish further findings as they become available. No threat actor has claimed the intrusion and no attribution has been reported by any outlet as of 2026-09-18.
MITRE ATT&CK techniques used in TL-2026-2566
Execution
T1059 Command and Scripting Interpreter
Persistence
Credential Access
T1110.004 Credential Stuffing; T1528 Steal Application Access Token
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Reconnaissance
Affected products and versions in Gyazo Data Breach
- Helpfeel Inc. — Gyazo (image upload server / image-sharing platform)
Vulnerable versions: Gyazo production image upload server and backing database, active as of 2026-09-11
Fixed in: Patched by Helpfeel on 2026-09-12; specific version/build not publicly disclosed - Helpfeel Inc. — Helpfeel (help-center/FAQ SaaS) and Cosense (formerly Scrapbox)
Remediation for Gyazo Data Breach
Patches
- Image upload server vulnerability remediated by Helpfeel on 2026-09-12; specific vulnerability class/CWE not publicly disclosed by the vendor
Immediate actions
- Blocked the identified unauthorized access routes and terminated the attacker's active connections (completed by Helpfeel on 2026-09-12)
- Patched the exploited image upload server vulnerability the same day it was identified (2026-09-12)
- Temporarily suspended/restricted image delivery and viewing of existing images to limit further exposure (from 2026-09-14)
- Invalidated and restricted existing authentication and session tokens (2026-09-15)
- All Gyazo/Helpfeel account holders should change their Gyazo password immediately, and change it on any other service where the same or a similar password was reused
Workarounds
- Restrict or re-verify exposure of legacy (pre-January 2019) Gyazo image links until Helpfeel completes remediation of the metadata exposure
- Do not rely on Gyazo private-image passphrases for sensitive content until Helpfeel confirms passphrase/credential rotation
Longer-term hardening
- Users should review and re-authorize or revoke X (Twitter) and Google SSO integrations linked to their Gyazo account given the exposed integration/session tokens
- Treat previously 'private' Gyazo capture links as compromised; do not rely on 32-character image-ID secrecy as sole access control going forward, particularly for pre-2019 uploads
- Monitor for phishing, credential-stuffing, and social-engineering attempts referencing exposed Gyazo/Helpfeel account data (Helpfeel and outlets both flagged secondary phishing risk)
- Helpfeel should confirm and publicly clarify whether previously issued login session IDs were fully invalidated (rather than merely 'restricted'), and whether new-IP login verification is enforced, to close the residual session-hijack window
- Helpfeel should complete and publish the external forensic investigation, including root-cause/vulnerability-class disclosure, once available
Timeline of Gyazo Data Breach
- Helpfeel detected suspicious activity the same evening and began incident investigation and response.
- Evening (Japan time): an unauthorized third party exploited a vulnerability in Gyazo's image upload server, gaining unauthorized access to Helpfeel's systems and executing arbitrary commands.
- Helpfeel patched the exploited image upload server vulnerability the same day access was blocked, closing a roughly 24-hour detection-to-remediation window.
- Early morning: Helpfeel blocked the identified access routes and terminated the attacker's unauthorized connections.
- Helpfeel confirmed unauthorized disclosure of data had occurred and suspended image delivery as a precautionary measure.
- Helpfeel submitted a breach report to Japan's Personal Information Protection Commission (PPC).
- Helpfeel implemented additional protective measures, invalidating and restricting existing authentication/session tokens, though The Hacker News later reported the completeness of session-ID invalidation remained unclear.
- Helpfeel published a public notice and apology disclosing the breach's scope (~23.62M user records, ~492.4M image metadata records), confirming its Helpfeel and Cosense products on separate architectures were not confirmed affected, and urged all users to change their Gyazo password and any reused passwords elsewhere.
- The Hacker News, DataBreaches.Net, Cybernews, TechRadar, MLex, SQ Magazine, and other outlets published independent coverage and analysis of the disclosure, including risk analysis of the exposed image-ID access-control model and residual session-validity questions.
- SecurityWeek published coverage of the breach; Helpfeel's external forensic investigation remains ongoing with further findings pending.
Sources cited for Gyazo Data Breach
- 23 Million User Records Compromised in Gyazo Data Breach
- Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
- Gyazo data breach leaves over 23 million user records exposed, includes half a billion metadata points
- Gyazo breach exposes 23.62 million user records and 490 million image records — PII and metadata exposed in huge attack
- Japan's Helpfeel says Gyazo data breach exposed 24m user records
- Gyazo Breach Exposes Link IDs Behind Private Captures
- Security Check-in Quick Hits: Cisco ISE Zero-Day Under Active Attack, Gyazo's 23.6M-Record Breach, and FamousSparrow's SparroWocky Espionage Push
More in data breach
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
- Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial and Passport Data
- TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentials
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak
Detection coverage for TL-2026-2566
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2566 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.