About 23.62 million user records and roughly 490 million image metadata records were exposed in a breach of Gyazo, Helpfeel’s image‑sharing service, the Kyoto‑based company said in a notice published Wednesday.
How the attacker gained access: the image upload server and arbitrary commands
Helpfeel said the intruder exploited a vulnerability in Gyazo’s image upload server, used that access to run arbitrary commands on Helpfeel’s systems, and obtained access to Gyazo’s database. The company has not specified the exact nature of the flaw. After identifying suspicious activity on the evening of September 11 (Japan time), Helpfeel said it blocked the access routes it had identified, cut the attacker’s connections, and fixed the vulnerability by the early hours of September 12.
Data types exposed and the scale of the leak
Helpfeel reported approximately 23.62 million user records and about 490 million image metadata records were exposed. The user records can vary by account but may include name fields (any text users entered), email addresses, password hashes, user IDs, device IDs, login session IDs, X (formerly Twitter) integration tokens (if connected), Google SSO email addresses (if connected), profile information, language preference, registration and last‑login timestamps, subscription plan and billing status (Helpfeel said no credit card numbers or other payment details were exposed), and usage statistics. Helpfeel said the 23.62 million figure counts records and includes anonymous accounts with no registered email address; the company is still working out how many people had personal information exposed.
Helpfeel also listed exposed image‑related fields and related information: image IDs (used to build image URLs), IP addresses used for uploads, User‑Agent strings, EXIF location data (if the image contained it), OCR text extracted from images, image titles, source URLs and other metadata, and hashed passphrases for private images. The company said the 490 million metadata records are mostly for images registered in January 2019 or earlier and represent about 14.4% of Helpfeel’s image‑related data. A further 2.4 million images’ metadata was pulled separately using “specific filtering criteria”; Helpfeel has not said whether that second set overlaps the larger set or what the filter was.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildImage IDs, private captures, and viewing risk
Every Gyazo capture gets a link built from a 32‑character image ID; Gyazo’s help pages say a capture stays private until its link is shared and that anyone who has the link can see it. The help pages also describe the ID as long enough that a link “can't be guessed.” Helpfeel said the exposed image IDs could be used to view images without permission and that it has temporarily disabled viewing of some images to prevent further harm.
Helpfeel warned that the attacker obtained a list identifying private images and said it “cannot rule out the possibility that the third party may have viewed some private images.” On Gyazo, a private capture can mean one set to “Only me” (which Gyazo’s help pages say cannot be viewed even by someone who knows the link) or one locked with a password; both settings are available only on paid plans. Helpfeel has not said which type of private images the attacker may have viewed or how they could have been accessed.
The OCR text field comes from a Gyazo feature that reads text in a user’s captures so they can search it; Gyazo’s help pages describe it as a paid feature that users enable and that then scans the account’s images, and those pages state, “Only you can see OCR results.” Helpfeel said it has not found any loss of image data but has temporarily disabled delivery for some images; it has not said which images are disabled or how users can tell whether their captures are in the affected sets.
Timeline and disclosure: September 11–16
Helpfeel said it noticed suspicious activity on the evening of September 11, blocked and fixed the vulnerability by the early hours of September 12, and suspended image delivery for some images on September 14. While images were failing to load, Gyazo’s public notices described the interruption as maintenance; when Helpfeel suspended image delivery on September 14 the product‑updates page said delivery had been suspended for some images “due to emergency maintenance.” After new uploads resumed on September 15, a second notice said, “Some images remain unavailable due to emergency maintenance.”
Helpfeel said it confirmed on September 14 that data had been exposed, reported the incident to Japan’s Personal Information Protection Commission on September 15, and published its user notice on September 16. Outside specialists are now conducting a forensic investigation, Helpfeel said, and it will email users it identifies as affected while posting notices on Gyazo’s website for anonymous accounts. The company is handling questions by its support form.
What this means for technologists, Gyazo users, and Japan’s Personal Information Protection Commission
- Technologists and security teams: the breach centers on an image upload server vulnerability, arbitrary command execution, and database access; Helpfeel’s statement that it has reviewed authentication data and taken “the necessary measures, including invalidation and restrictions” highlights two technical priorities — determining which credentials and session tokens were invalidated and confirming whether exposed session IDs remain valid (Helpfeel has not said whether they do).
- Gyazo users and account holders: Helpfeel asked every Gyazo user to change their password and to change it on any other service that uses the same or a similar one, and to watch for suspicious emails or messages related to the incident; Helpfeel also said no payment information was exposed.
- Japan’s Personal Information Protection Commission (PIPC): Helpfeel reported the incident to the PIPC on September 15 and will be the recipient of whatever regulatory review or required disclosures follow the notification.
Helpfeel’s next steps, as stated, are a forensic investigation by outside specialists and direct notifications to users it identifies as affected. The company has emphasized temporary measures — disabling some image viewing and reviewing authentication data — while it finishes the investigation and communicates with users and regulators.
https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html




