Gyazo server flaw exploited to steal 23.6 million user records
Attackers exploited a server flaw to steal 23.6 million Gyazo user records and 490 million image metadata records, including password hashes and private-image lists.
Gyazo, a screenshot-sharing service operated by Japan's Helpfeel with about 23 million users, confirmed attackers exploited a server vulnerability on September 11, 2026, accessing its database. Approximately 23.62 million user records were stolen, including names, email addresses, password hashes, login session IDs, X integration tokens, and subscription data. Separately, 490 million image metadata records were exposed, including upload IP addresses, User-Agent strings, EXIF location data, OCR text, and hashed passphrases for private images. Gyazo took the platform offline, patched the flaw, and is notifying affected users with external expert assistance.