ZeroHour
Product

Gyazo

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Image-sharing service Gyazo disclosed a breach exposing about 23.62 million user records, including emails and password hashes, plus 490 million image metadata records.

Helpfeel, the Kyoto-based operator of image-sharing service Gyazo, disclosed that a security breach exposed approximately 23.62 million user records, including email addresses and password hashes. The breach also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier. The company published its notice on Wednesday, September 17, 2026.

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Helpfeel's Gyazo image-sharing service disclosed a breach exposing 23.62 million user records and 490 million image metadata records via a compromised upload server.

An attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database, exposing about 23.62 million user records including names, email addresses, password hashes, session IDs, and X integration tokens, plus roughly 490 million image metadata records, mostly from January 2019 or earlier. Leaked 32-character image IDs could enable unauthorized viewing of images, and Helpfeel cannot rule out that private images were viewed; metadata included EXIF location data and OCR text. Helpfeel detected the intrusion on September 11, 2026, blocked access and fixed the flaw, reported to Japan's Personal Information Protection Commission on September 15, and urged all users to change their passwords; no payment data was exposed.

The Hacker Newsupdated · 4h agofirst · 8h agoData breach in the wild 2 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.