ZeroHour
Victim

Helpfeel

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Gyazo Data Breach Exposes 23 Million User Records

Attackers exploited a flaw in Gyazo's image upload server, exposing 23.6 million user records and about 490 million image metadata entries.

Japanese software company Helpfeel is notifying Gyazo users that attackers exploited a vulnerability in the image upload server on September 11, ran malicious commands, and accessed a database with approximately 23.62 million user records before being locked out the next day. Stolen data includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile details and billing information. About 490 million image metadata records were also exposed, including upload IP addresses, User-Agent data, EXIF location information, OCR text and hashed passphrases for private images, plus a list of private images. Payment card data was not affected, remediation is complete, and the investigation is ongoing.

Security Affairs · 1d agoData breach in the wild 5 sources

Gyazo server flaw exploited to steal 23.6 million user records

Attackers exploited a server flaw to steal 23.6 million Gyazo user records and 490 million image metadata records, including password hashes and private-image lists.

Gyazo, a screenshot-sharing service operated by Japan's Helpfeel with about 23 million users, confirmed attackers exploited a server vulnerability on September 11, 2026, accessing its database. Approximately 23.62 million user records were stolen, including names, email addresses, password hashes, login session IDs, X integration tokens, and subscription data. Separately, 490 million image metadata records were exposed, including upload IP addresses, User-Agent strings, EXIF location data, OCR text, and hashed passphrases for private images. Gyazo took the platform offline, patched the flaw, and is notifying affected users with external expert assistance.

BleepingComputerupdated · 1d agofirst · 1d agoData breach in the wild 5 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.