A security breach at Gyazo, Helpfeel’s image-sharing service, has exposed about 23.62 million user records along with metadata linked to roughly 490 million images, the Kyoto-based company said.
The exposed user records include email addresses, password hashes, user IDs, device IDs and login session IDs. Depending on the account, the data may also contain names or nicknames, profile information, language preferences, registration and login timestamps, subscription and billing status, usage statistics, Google single sign-on email addresses and X integration tokens. Helpfeel said payment information such as credit card numbers was not exposed.
The 23.62 million figure represents records rather than individual users. It includes anonymous accounts that do not have registered email addresses, and Helpfeel said it is still determining how many people had their personal information exposed.
The breach also affected about 490 million image metadata records, most of which relate to images registered in January 2019 or earlier. The exposed information includes Gyazo image IDs, IP addresses used for uploads, User-Agent details, EXIF location data where available, OCR text, image titles, source URLs and other metadata. Hashed passphrases for private images were also included.
The image IDs are particularly significant because they form part of the URLs used to access Gyazo captures. Helpfeel said the exposed IDs could potentially be used to view images without permission and has temporarily disabled viewing of some affected images. The company said its investigation has not found evidence that image data itself was lost, but it cannot rule out the possibility that the attacker viewed some private images.
Helpfeel said the attacker gained access through a vulnerability in Gyazo’s image upload server. The attacker was able to execute arbitrary commands on Helpfeel’s systems and access the Gyazo database. The company has not disclosed what type of vulnerability was involved.
A separate set of metadata covering about 2.4 million images was also accessed using what Helpfeel described as specific filtering criteria. The company has not disclosed what criteria were used or whether those records overlap with the larger set of affected metadata.
The breach also involved information identifying private images. Gyazo offers privacy options including images restricted to the account owner and password-protected images, although Helpfeel has not specified which types of private images were involved or whether they could have been accessed by the attacker.
Helpfeel said it detected suspicious activity on the evening of September 11 in Japan. By the early hours of September 12, the company had blocked the access routes it identified, disconnected the attacker and fixed the vulnerability. It later confirmed that data had been exposed on September 14.
Gyazo temporarily experienced image delivery problems during the response. Public notices initially described the disruption as emergency maintenance, while some images remained unavailable even after new uploads resumed.
Helpfeel reported the incident to Japan’s Personal Information Protection Commission on September 15 and published its security notice on September 16. The company said external specialists are conducting a forensic investigation and that users identified as affected will be contacted by email. Anonymous users will receive notices through the Gyazo website.
Helpfeel has urged all Gyazo users to change their passwords and to update passwords on other services where the same or a similar password was used. Users have also been advised to remain alert for suspicious emails or messages related to the incident.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The company said its other products, Helpfeel and Cosense, operate on separate systems and that it has found no evidence that their data was exposed. However, Gyazo images embedded in those services may remain unavailable while image delivery restrictions are in place.
Gyazo Data Breach Exposes 23.6 Million User Records and Image Metadata



