Gyazo upload-server flaw exposed 23.62 million user records and ~490 million image metadata records
Helpfeel confirmed attackers exploited a vulnerability in Gyazo's image upload server on September 11, 2026, stealing 23.62 million user records and roughly 490 million image metadata records; viewing of private images cannot be ruled out.
Japanese image-sharing service Gyazo, operated by Helpfeel, was breached after attackers exploited a vulnerability in its image upload server to execute arbitrary commands on September 11, 2026, with access routes blocked by early September 12 (Help Net Security dates the attack to September 11; Infosecurity Magazine describes September 11 as the disclosure date). Stolen data includes 23.62 million user records containing names, email addresses, password hashes, session IDs, and X integration tokens, plus about 490 million image metadata records covering image IDs, source/upload IPs, user agents, EXIF location data, OCR-extracted text, titles, source URLs, and hashed passphrases protecting private images. No payment data was taken. Because the metadata allows reconstructing image URLs, Helpfeel disabled or paused image viewing/delivery, reset sessions, remediated the flaw, urged users to change passwords, and warned of follow-on phishing risk. The company reported the incident to Japan's Personal Information Protection Commission on September 15. Experts noted developers' screenshots often contain credentials and terminal output, though most exposed data predates January 2019, which mitigates some impact.
- Attackers exploited a vulnerability in Gyazo's image upload server to execute arbitrary commands on September 11, 2026; access routes were blocked by early September 12
- 23.62 million user records stolen, including names, email addresses, password hashes, session IDs, and X integration tokens (Infosecurity Magazine rounds this to 'nearly 24 million')
- About 490 million image metadata records exposed, including image IDs, source/upload IPs, user agents, EXIF location data, OCR-extracted text, titles, source URLs, and hashed passphrases protecting private images
- No payment data was affected
- A list of private images was obtained and metadata could allow reconstruction of image URLs; Helpfeel cannot rule out that private images were viewed and disabled/paused image viewing and delivery
- Incident reported to Japan's Personal Information Protection Commission on September 15, 2026
- Helpfeel remediated the flaw, reset sessions, and urged users to change passwords, warning of follow-on phishing risk
- Experts noted developers' screenshots often contain credentials and terminal output, though most of the exposed data predates January 2019, mitigating some impact
Coverage timelineoldest first · each row is one article
- · 5d agoHackers exploit Gyazo server flaw to steal 23.6 million user records
Help Net Security· 90
Helpfeel confirmed attackers exploited a Gyazo upload-server flaw, stealing 23.62 million user records and roughly 490 million image metadata records.
- · 5d agoExperts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Infosecurity Magazine· 85
Attackers exploited a Gyazo upload-server vulnerability, exposing 24 million user records and 490 million metadata records including IPs, EXIF locations and OCR text.