Gyazo data breach (2026): what was exposed and what to do

Updated Corrections

September 17, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

What happened

Helpfeel Inc., the Kyoto company behind the screenshot and image-sharing service Gyazo, said an attacker exploited a vulnerability in Gyazo's image upload server on September 11, 2026 Japan time, reached its servers, and ran commands there. Helpfeel detected suspicious activity that evening and blocked the access routes it had identified by the early hours of September 12.

In a notice published September 16, Helpfeel said roughly 23.62 million user-related records and roughly 490 million image metadata records were disclosed without authorization, along with metadata for about 2.4 million more images pulled under specific filter criteria. The image metadata covers about 14.4 percent of all image-related data the company holds, mostly images registered in or before January 2019.

Those are record counts, not people. Helpfeel said the user-record total includes anonymous accounts with no registered email address, that one person can account for several records, and that it has not yet determined how many individuals are affected.

The company patched the vulnerability on September 12, ran emergency maintenance on September 14 that stopped delivery of some images, and added further measures on September 15, when image delivery resumed for new uploads while some older images stayed unavailable. It reported the breach to Japan's Personal Information Protection Commission on September 15, engaged outside forensic specialists, and said its investigation continues. The company has not said whether it will notify affected users individually. Helpfeel said it has confirmed no unauthorized disclosure from its separate Helpfeel and Cosense products, though images embedded in those products were affected by the delivery pause.

Sources

What data was exposed

The following types of personal data were compromised. Helpfeel said the types and extent vary by user.

In the user records:

  • Name or nickname, meaning whatever text the user entered
  • Email address
  • Password hash
  • User ID, device ID, and login session ID
  • X (formerly Twitter) integration token, where connected
  • The email address tied to Google single sign-on, where connected
  • Profile details, language preference, registration date, and last login
  • Subscription plan and billing status
  • Usage statistics

In the image metadata:

  • Image ID, which is the piece used to build an image's URL
  • The IP address and browser user-agent used for the upload
  • EXIF location data, where the image carried it
  • Text extracted from the image by OCR
  • Image title, source URL, and related metadata
  • Hashed passphrase for private images

Helpfeel has not said how the passwords were hashed, so treat the strength of that protection as unknown and change the password rather than assume it holds. The company said no payment information, including credit card numbers, was disclosed. It also said that because the metadata can be used to construct image URLs, the corresponding images could be viewed without authorization, that it cannot rule out that some private images were viewed, and that it has not confirmed any loss of the image files themselves.

Breach details

Detail Value
Breach name Gyazo (Helpfeel Inc.)
Date September 11 to 12, 2026
Disclosed September 16, 2026
Accounts affected 23.62 million user records and 490 million image metadata records; the number of individuals is not yet determined
Domain gyazo.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Helpfeel Inc. or Gyazo; it reflects a publicly reported security incident.

For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.

What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • Change your Gyazo password, and change it anywhere you reused it or a close variant. Helpfeel asked every user to do this.
  • If you connected Google or X to your Gyazo account, review those connected apps and revoke access you no longer need.
  • Turn on two-factor authentication on the email address you used for Gyazo. A leaked email and password hash pair is most useful to an attacker who can also reach your inbox.
  • Think about what your old screenshots contained. Anything you captured before 2019 is most likely in the exposed metadata, and the text in those images was extracted by OCR. Screenshots of letters, invoices, tickets, or account pages may carry your address or account numbers.
  • Treat unexpected email about Gyazo or Helpfeel as possible phishing, and use the contact form on help.gyazo.com rather than links in a message.
  • Don't wait for an email. Helpfeel's notice doesn't say whether it will contact individual users, so check its notice page for updates.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.