23 Million User Records Compromised in Gyazo Data Breach

23 Million User Records Compromised in Gyazo Data Breach

A major data breach has compromised the sensitive information of over 23 million users of Japan-based software company Helpfeel’s image-sharing service, Gyazo. The breach occurred when a hacker exploited a vulnerability on the platform’s image upload server, allowing them to access a database containing user records.

Gyazo is a popular cross-platform tool used by millions worldwide to capture screenshots, GIFs, and short screen recordings, generating shareable links instantly. The compromised data includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing details. However, Helpfeel assures that payment card information was not accessed.

The breach occurred on September 11 when the hacker took advantage of a vulnerability in Gyazo’s image upload server to execute malicious commands. The attacker was subsequently kicked out the next day, but not before accessing the database containing user records. It is worth noting that approximately 23.62 million affected records include anonymous accounts with no registered email address or similar information.

The compromised data also includes image metadata for around 490 million images uploaded by users, which could potentially allow threat actors to reconstruct and access URLs associated with these images. Additionally, a list of private images has been compromised, although the company has not disclosed any information on the volume affected.

Helpfeel is taking steps to notify users about the breach and is continuing to determine the actual number of individuals whose personal information was disclosed without authorization. This incident highlights the importance of robust security measures in protecting sensitive user data, especially when it comes to cloud-based services like Gyazo.

For those using Gyazo or similar image-sharing platforms, this incident serves as a reminder to exercise caution and regularly review account settings for potential vulnerabilities. It is also essential to use strong, unique passwords and enable two-factor authentication whenever possible.

Ultimately, the Gyazo data breach underscores the ongoing need for robust cybersecurity measures in protecting sensitive user information and preventing unauthorized access. As more services move online, the risk of data breaches will only continue to grow unless adequate safeguards are put in place to mitigate these risks.


Source: SecurityWeek — 2026-09-18