Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit

Gyazo Data Breach (TL-2026-2566) is a high-severity data breach, first published 2026-09-18. It has no confirmed attribution, affects Helpfeel Inc. Gyazo (image upload server / image-sharing platform), maps to 10 MITRE ATT&CK techniques (T1059, T1078, T1110.004), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2566

Threat ID
TL-2026-2566
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-18
Last reviewed
2026-09-18
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, softwaresaas, mediaandpublishing
Target regions
japan, Global
Detection rules
9
Indicators of compromise
9

Helpfeel Inc., the Kyoto-based operator of the Gyazo image-sharing/screenshot service, disclosed on 2026-09-16 that a third party exploited a vulnerability in Gyazo's image upload server on 2026-09-11 to gain unauthorized access and execute arbitrary commands, ultimately reaching Gyazo's database. Approximately 23.62 million user records (names, emails, password hashes, device/session IDs, X/Twitter and Google SSO tokens, billing status) and roughly 492.4 million image metadata records (image IDs, IPs, EXIF location, OCR text, hashed private-image passphrases) were exposed; payment card data was not affected.

How Gyazo Data Breach works

On the evening of September 11, 2026 (Japan time), an unauthorized third party exploited a vulnerability in the image upload server operated by Helpfeel Inc. for its Gyazo image-sharing and screenshot service, gaining unauthorized access to Helpfeel's systems and executing arbitrary commands. Multiple secondary outlets (The Hacker News, RodTrent's roundup) characterize this as a critical server-side flaw in the upload component, consistent with unsafe file-handling or input-validation weaknesses, though Helpfeel itself has not disclosed the specific vulnerability class or CVE. Helpfeel detected the suspicious activity the same evening and began an incident response; by the early hours of September 12 the company had blocked the identified access routes, terminated the attacker's active connections, and patched the exploited vulnerability — a containment window of roughly 24 hours from detection to remediation.

Helpfeel's own notice states that its other products, Helpfeel (the help-center/FAQ SaaS) and Cosense (formerly Scrapbox), run on "different system architectures" and showed no confirmed unauthorized disclosure, indicating the compromise was scoped to the Gyazo image upload server and its backing database rather than Helpfeel's broader corporate environment.

On September 14, Helpfeel confirmed that data had been unauthorizedly disclosed and suspended image delivery as a precaution. On September 15, the company implemented additional protective measures — invalidating and restricting existing authentication/session tokens — and submitted a breach report to Japan's Personal Information Protection Commission (PPC), as required under Japan's Act on the Protection of Personal Information. On September 16, Helpfeel published a public notice and apology disclosing the scope of the incident and urging all Gyazo users to change their password, and to change it on any other service where the same or a similar password was reused.

The exposed user dataset comprises approximately 23.62 million records, including accounts with no registered email (anonymous accounts). Fields include names, email addresses, password hash values, user IDs, device IDs, login session IDs, X (formerly Twitter) integration tokens, Google SSO linkage emails, profile/language preferences, registration and login dates, subscription plan, and billing status; Helpfeel states payment card numbers were not compromised. The Hacker News additionally reported that whether the exposed login session IDs remain cryptographically valid — and whether Gyazo's new-IP login verification would block their reuse — was not clearly resolved by Helpfeel's disclosure at the time of reporting, leaving open a residual account-takeover/session-hijack risk pending full confirmation of token invalidation.

Separately, roughly 490 million image metadata records tied to images registered before January 2019, plus an additional 2.4 million records retrieved via what Helpfeel described as "specific filtering criteria," were exposed. This metadata includes the 32-character image IDs that compose Gyazo share URLs (Gyazo markets these as effectively "unguessable," using ID secrecy as the primary access control for default-privacy images), uploader IP addresses and User-Agent strings, EXIF geolocation data embedded in images, OCR text Gyazo extracts from paid users' captures (which Gyazo's own documentation states only the uploader can see), image titles/source URLs, and hashed passphrases protecting private images. Because the image IDs themselves were exposed, the sole access-control mechanism protecting many default-privacy captures has been defeated, making URL reconstruction and unauthorized viewing of historical images feasible without any enumeration or brute-forcing — the leaked IDs are themselves the secret. Reporting also indicates the attacker obtained a list specifically identifying which images were flagged private, and Helpfeel has stated it "cannot rule out the possibility that the third party may have viewed some private images." Helpfeel has temporarily disabled delivery of some existing (unnamed subset of) images and resumed delivery only for newly uploaded content while the investigation continues; because the image ID is the sole secret, deletion — not rotation — is the only mitigation available for already-exposed links. An external forensics firm is conducting an ongoing investigation, with Helpfeel committing to publish further findings as they become available. No threat actor has claimed the intrusion and no attribution has been reported by any outlet as of 2026-09-18.

MITRE ATT&CK techniques used in TL-2026-2566

Execution

T1059 Command and Scripting Interpreter

Persistence

T1078 Valid Accounts

Credential Access

T1110.004 Credential Stuffing; T1528 Steal Application Access Token

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Reconnaissance

T1589.001 Credentials; T1589.002 Email Addresses

Affected products and versions in Gyazo Data Breach

  • Helpfeel Inc. — Gyazo (image upload server / image-sharing platform)
    Vulnerable versions: Gyazo production image upload server and backing database, active as of 2026-09-11
    Fixed in: Patched by Helpfeel on 2026-09-12; specific version/build not publicly disclosed
  • Helpfeel Inc. — Helpfeel (help-center/FAQ SaaS) and Cosense (formerly Scrapbox)

Remediation for Gyazo Data Breach

Patches

  • Image upload server vulnerability remediated by Helpfeel on 2026-09-12; specific vulnerability class/CWE not publicly disclosed by the vendor

Immediate actions

  • Blocked the identified unauthorized access routes and terminated the attacker's active connections (completed by Helpfeel on 2026-09-12)
  • Patched the exploited image upload server vulnerability the same day it was identified (2026-09-12)
  • Temporarily suspended/restricted image delivery and viewing of existing images to limit further exposure (from 2026-09-14)
  • Invalidated and restricted existing authentication and session tokens (2026-09-15)
  • All Gyazo/Helpfeel account holders should change their Gyazo password immediately, and change it on any other service where the same or a similar password was reused

Workarounds

  • Restrict or re-verify exposure of legacy (pre-January 2019) Gyazo image links until Helpfeel completes remediation of the metadata exposure
  • Do not rely on Gyazo private-image passphrases for sensitive content until Helpfeel confirms passphrase/credential rotation

Longer-term hardening

  • Users should review and re-authorize or revoke X (Twitter) and Google SSO integrations linked to their Gyazo account given the exposed integration/session tokens
  • Treat previously 'private' Gyazo capture links as compromised; do not rely on 32-character image-ID secrecy as sole access control going forward, particularly for pre-2019 uploads
  • Monitor for phishing, credential-stuffing, and social-engineering attempts referencing exposed Gyazo/Helpfeel account data (Helpfeel and outlets both flagged secondary phishing risk)
  • Helpfeel should confirm and publicly clarify whether previously issued login session IDs were fully invalidated (rather than merely 'restricted'), and whether new-IP login verification is enforced, to close the residual session-hijack window
  • Helpfeel should complete and publish the external forensic investigation, including root-cause/vulnerability-class disclosure, once available

Timeline of Gyazo Data Breach

  • Helpfeel detected suspicious activity the same evening and began incident investigation and response.
  • Evening (Japan time): an unauthorized third party exploited a vulnerability in Gyazo's image upload server, gaining unauthorized access to Helpfeel's systems and executing arbitrary commands.
  • Helpfeel patched the exploited image upload server vulnerability the same day access was blocked, closing a roughly 24-hour detection-to-remediation window.
  • Early morning: Helpfeel blocked the identified access routes and terminated the attacker's unauthorized connections.
  • Helpfeel confirmed unauthorized disclosure of data had occurred and suspended image delivery as a precautionary measure.
  • Helpfeel submitted a breach report to Japan's Personal Information Protection Commission (PPC).
  • Helpfeel implemented additional protective measures, invalidating and restricting existing authentication/session tokens, though The Hacker News later reported the completeness of session-ID invalidation remained unclear.
  • Helpfeel published a public notice and apology disclosing the breach's scope (~23.62M user records, ~492.4M image metadata records), confirming its Helpfeel and Cosense products on separate architectures were not confirmed affected, and urged all users to change their Gyazo password and any reused passwords elsewhere.
  • The Hacker News, DataBreaches.Net, Cybernews, TechRadar, MLex, SQ Magazine, and other outlets published independent coverage and analysis of the disclosure, including risk analysis of the exposed image-ID access-control model and residual session-validity questions.
  • SecurityWeek published coverage of the breach; Helpfeel's external forensic investigation remains ongoing with further findings pending.

Sources cited for Gyazo Data Breach

More in data breach

Detection coverage for TL-2026-2566

As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2566 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats