{"id":257096,"date":"2026-09-22T12:23:33","date_gmt":"2026-09-22T09:23:33","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=257096"},"modified":"2026-09-22T12:23:33","modified_gmt":"2026-09-22T09:23:33","slug":"gyazo-breach-23-6m-user-records-stolen-via-server-flaw","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/257096\/gyazo-breach-23-6m-user-records-stolen-via-server-flaw\/","title":{"rendered":"Gyazo Breach: 23.6M User Records Stolen via Server Flaw"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Japanese software company Helpfeel confirmed a data breach on its screenshot-sharing platform Gyazo where attackers exploited an image upload server vulnerability.<br>&#8211; The incident resulted in the unauthorized access of approximately 23.62 million user records and metadata linked to hundreds of millions of images.<br>&#8211; Stolen data includes names, email addresses, password hashes, and device IDs, though no payment information was compromised.<br>&#8211; Helpfeel has blocked the attacker&#8217;s access, reported the incident to Japanese authorities, and is notifying affected users via email and web interface.<br>&#8211; Users are advised to change their passwords immediately as investigators continue to determine if private images were viewed.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<h2 class=\"wp-block-heading\">Critical Vulnerability Exposes Millions of Gyazo Users<\/h2>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/japanese\/\" class=\"acp-entity-link\" data-entity-id=\"1210\" data-entity-category=\"Language\" title=\"Learn more about Japanese\" target=\"_blank\" rel=\"noopener noreferrer\">Japanese<\/a> technology firm <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/helpfeel\/\" class=\"acp-entity-link\" data-entity-id=\"300009\" data-entity-category=\"Organization\" title=\"Learn more about Helpfeel\" target=\"_blank\" rel=\"noopener noreferrer\">Helpfeel<\/a><\/strong> has officially acknowledged a severe data breach affecting its popular screenshot-sharing service, <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/gyazo\/\" class=\"acp-entity-link\" data-entity-id=\"300008\" data-entity-category=\"product\" title=\"Learn more about Gyazo\" target=\"_blank\" rel=\"noopener noreferrer\">Gyazo<\/a><\/strong>. The incident involved attackers leveraging a critical flaw in the platform\u2019s image upload server to exfiltrate approximately <strong>23.62 million user records<\/strong>. Alongside personal account data, the breach compromised metadata linked to hundreds of millions of images stored on the cloud-based platform.<\/p>\n\n<p class=\"wp-block-paragraph\">Gyazo operates as a utility for capturing and sharing screen recordings and screenshots, automatically generating shareable links for use across social media and messaging platforms. The security failure occurred on <strong>September 11<\/strong>, when an unauthorized actor exploited the system vulnerability to execute arbitrary commands within Gyazo\u2019s infrastructure. Helpfeel\u2019s security team identified the suspicious activity later that evening. By the early morning of <strong>September 12<\/strong>, the company had successfully blocked the intrusion vectors and severed the attacker\u2019s connections.<\/p>\n\n<h2 class=\"wp-block-heading\">Scope of Compromised Data and Metadata<\/h2>\n\n<p class=\"wp-block-paragraph\">The investigation revealed that the intruder accessed the core database, leading to the unauthorized disclosure of sensitive user information. The stolen dataset contains a wide array of identifiers and authentication details.<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cOur subsequent investigation confirmed that the third party had accessed Gyazo\u2019s database and that user information and metadata associated with uploaded images had been disclosed without authorization,\u201d the company stated in its official report.<\/p>\n\n<p class=\"wp-block-paragraph\">The compromised user records encompass <strong>names, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens, <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/256684\/gyazo-breach-exposes-23-6m-user-records\/\" class=\"acp-article-link\" data-article-id=\"256684\" title=\"Gyazo Breach Exposes 23.6M User Records\" target=\"_blank\" rel=\"noopener noreferrer\">Google SSO<\/a> email addresses, profile information, language preferences, registration and login timestamps, subscription plans, and billing status<\/strong>. Despite the breadth of the exposure, Helpfeel emphasized that financial data remained secure.<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cWe have confirmed that no payment information, including credit card numbers, was disclosed without authorization.\u201d<\/p>\n\n<p class=\"wp-block-paragraph\">Beyond individual accounts, the scope of the data theft extended significantly into image metadata. Approximately <strong>490 million metadata records<\/strong> were accessed, primarily comprising images uploaded in or before <strong>January 2019<\/strong>. This represents roughly <strong>14.4%<\/strong> of all image data hosted on the platform. Additionally, hackers utilized specific filtering techniques to extract metadata from another <strong>2.4 million images<\/strong>. This secondary batch included image IDs, upload IP addresses, user agents, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases used to protect private files.<\/p>\n\n<h2 class=\"wp-block-heading\">Privacy Concerns and Ongoing Investigation<\/h2>\n\n<p class=\"wp-block-paragraph\">A particularly alarming aspect of the breach is the potential exposure of private content. The attackers obtained a comprehensive list identifying which images were designated as private by users.<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cWe have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation,\u201d the company added.<\/p>\n\n<p class=\"wp-block-paragraph\">Helpfeel noted that there is currently no evidence suggesting data was breached from its other services, <strong>Helpfeel<\/strong> and <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cosense\/\" class=\"acp-entity-link\" data-entity-id=\"300010\" data-entity-category=\"Organization\" title=\"Learn more about Cosense\" target=\"_blank\" rel=\"noopener noreferrer\">Cosense<\/a><\/strong>. However, because Gyazo paused image delivery to contain the threat, some images embedded in those other tools may remain temporarily unavailable.<\/p>\n\n<h2 class=\"wp-block-heading\">User Remediation and Service Status<\/h2>\n\n<p class=\"wp-block-paragraph\">Helpfeel reported the incident to Japan\u2019s <strong>Personal Information Protection Commission<\/strong> on September 15. The company is now initiating notification procedures, sending emails to registered users and displaying alerts via the Gyazo web interface for anonymous accounts lacking registered email addresses.<\/p>\n\n<p class=\"wp-block-paragraph\">In light of the compromise, Helpfeel issued urgent guidance to its user base regarding account security.<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cWe ask all Gyazo users to change their passwords,\u201d the notice reads, extending the same advice to any other account sharing the same or a similar password.<\/p>\n\n<p class=\"wp-block-paragraph\">The company expressed regret for the disruption caused by the attack.<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cWe sincerely apologize to all Gyazo users and other affected parties for the significant concern and inconvenience caused by this incident,\u201d Helpfeel wrote.<\/p>\n\n<p class=\"wp-block-paragraph\">As of the latest update, Gyazo\u2019s homepage displays a maintenance notice indicating that the service remains offline. The company has not yet provided a timeline for when full functionality will be restored.<\/p>\n\n<em>(Source: <a href='https:\/\/helpnetsecurity.com\/2026\/09\/21\/helpfeel-gyazo-data-breach\/' target='_blank'>Help Net Security<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>Helpfeel acknowledged a severe data breach on September 11 that compromised approximately 23.62 million user records and hundreds of millions of image metadata files through an exploited server vulnerability. The stolen information includes sensitive personal identifiers, authentication details, &#8230;<\/p>\n","protected":false},"author":1,"featured_media":257095,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,6579,3297,3327,3254],"tags":[257094,257093,257095,257502],"entities":[257100,257099,257098,38085,1770],"class_list":["post-257096","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-cosense","tag-gyazo","tag-helpfeel","tag-japans-personal-information","entity-cosense","entity-gyazo","entity-helpfeel","entity-japans-personal-information-protection-commission","entity-japanese"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257096","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=257096"}],"version-history":[{"count":2,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257096\/revisions"}],"predecessor-version":[{"id":257104,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257096\/revisions\/257104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/257095"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=257096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=257096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=257096"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=257096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}