23 Million User Records Compromised in Gyazo Data Breach

MediumSecurityWeek · Eduard Kovacs·

At a glance

Severity
Medium
Used in attacks
No flaws named
Reported by
1 outlet

Japanese software company Helpfeel is notifying users of its Gyazo image-sharing service that hackers have accessed their information.

Gyazo is a widely used cross-platform tool that lets users capture screenshots, GIFs, or short screen recordings and instantly generate shareable links.

Helpfeel revealed this week that it recently detected unauthorized access to Gyazo servers. A hacker exploited a vulnerability in its image upload server on September 11, enabling them to execute malicious commands. 

The attacker was kicked out the next day, but not before accessing a database storing roughly 23.6 million user records.

The compromised Gyazo user information includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing information.

Payment card information was not compromised, according to the vendor.

Advertisement. Scroll to continue reading.

“The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar information. We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization,” Helpfeel said

In addition to the user records, the attacker accessed roughly 490 million image metadata records. This metadata includes information that could allow threat actors to reconstruct and access URLs associated with images uploaded by users. 

A list of private images has also been compromised, but the company has not shared any information on volume. 

Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Related: 280,000 Impacted by Premier Medical Group Data Breach

Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.

Coverage

One outlet has carried this so far.

  1. SecurityWeekEstablished SourceFirst reported

    2026-09-18 11:38 UTC

Related stories