Gyazo, an image-sharing service operated by Helpfeel, announced a security breach that compromised approximately 23.62 million user records. The exposed data includes email addresses, password hashes, user IDs, device IDs, login session IDs, and other profile information. Additionally, about 490 million image metadata records, primarily from images uploaded before January 2019, were exposed. These metadata records include image IDs that could allow unauthorized viewing of images.
The attacker exploited a vulnerability in Gyazo's image upload server, which allowed them to execute arbitrary commands on Helpfeel's systems and access Gyazo's database. Helpfeel confirmed that no payment information, such as credit card numbers, was exposed. The exposed user records vary by user but can include names, email addresses, password hashes, user IDs, device IDs, login session IDs, X (formerly Twitter) integration tokens, Google SSO email addresses, profile information, language preferences, registration and last login dates, subscription plans, and billing status (without payment details).
The exposure of image IDs means that some private images could be viewed without permission, leading Helpfeel to temporarily disable viewing for certain images. Helpfeel has urged all Gyazo users to change their passwords immediately and to update passwords on any other services where they might have reused the same or similar credentials. Users are also advised to be vigilant for suspicious emails or messages related to this incident. While 23.62 million records were exposed, Helpfeel is still determining the exact number of individuals whose personal information was compromised, as the count includes anonymous accounts without registered email addresses.
Helpfeel stated it has reviewed the exposed authentication data and implemented necessary measures, including invalidation and restrictions, though specific invalidated items were not detailed. Gyazo typically uses a verification code for logins from new IP addresses, but it is unclear if exposed session IDs remain valid. The company's help pages previously stated that Gyazo image links, built from 32-character IDs, are secure enough that they "can't be guessed," but the breach indicates a compromise of this privacy mechanism.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Gyazo image-sharing platform confirmed a data breach on September 11, 2026, where attackers exploited a server vulnerability to steal approximately 23.6 million user records and 490 million image metadata records. This incident impacts a large user base, particularly in gaming communities, and exposes sensitive user information and image-related data, leading to the temporary suspension of the service.
Helpfeel's Gyazo image-sharing service experienced a data breach where hackers exploited a vulnerability to access approximately 23.6 million user records and 490 million image metadata records. This incident compromises user privacy and could lead to further exploitation of user data and image URLs.
Gyazo, an image-sharing service, experienced a security breach that exposed approximately 23.62 million user records, including email addresses and password hashes, along with 490 million image metadata records. This incident is significant because it compromises user privacy and security, potentially allowing unauthorized access to images and other services if users reused passwords.