23 Million User Records Compromised in Gyazo Data Breach
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Japanese software company Helpfeel is notifying users of its Gyazo image-sharing service that hackers have accessed their information.
Gyazo is a widely used cross-platform tool that lets users capture screenshots, GIFs, or short screen recordings and instantly generate shareable links.
Helpfeel revealed this week that it recently detected unauthorized access to Gyazo servers. A hacker exploited a vulnerability in its image upload server on September 11, enabling them to execute malicious commands.
The attacker was kicked out the next day, but not before accessing a database storing roughly 23.6 million user records.
The compromised Gyazo user information includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing information.
Payment card information was not compromised, according to the vendor.
Advertisement. Scroll to continue reading.
“The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar information. We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization,” Helpfeel said.
In addition to the user records, the attacker accessed roughly 490 million image metadata records. This metadata includes information that could allow threat actors to reconstruct and access URLs associated with images uploaded by users.
A list of private images has also been compromised, but the company has not shared any information on volume.
Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: 280,000 Impacted by Premier Medical Group Data Breach
Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.
Coverage
One outlet has carried this so far.
2026-09-18 11:38 UTC
Related stories
- TigerByte Cyber Emerges From Stealth With $3 Million in Funding
SecurityWeek · 2026-09-19
- North Korean WaterPlum hackers infected 30,000 devices worldwide
BleepingComputer · 2026-09-19
- ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
BleepingComputer · 2026-09-19
- Identity Visibility in 2026: The Foundation of Identity Security
The Hacker News · 2026-09-19
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The Hacker News · 2026-09-19