Customer Support software enterprise Helpfeel confirmed that an unauthorized intrusion compromised its popular image-sharing service Gyazo on September 11. An unidentified threat actor abused an Upload Server flaw to execute arbitrary commands, triggering a significant Gyazo data breach that compromised 23.62 million user records and 490 million image metadata entries. Could private screenshots stored across seven years be retrieved without permission? Forensic investigators established that while customer payment card numbers remained completely secure, millions of persistent account tokens and unguessable image addresses were exposed during the cyberattack [1].
Helpfeel Discloses Gyazo Data Breach
Helpfeel operates as an established Japanese organization employing more than 200 workers, providing modern Customer Support software, Intelligent Search tools, and an automated Support Agent. Corporate engineers detected anomalous system events late on September 11 in local Japanese time, discovering that an attacker had exploited an undisclosed vulnerability inside Gyazo’s Upload Server architecture. The intruder gained direct administrative access to underlying server nodes and compromised Gyazo’s central Database Server. By the early hours of September 12, security personnel severed the attacker’s active connections, blocked the identified intrusion pathways, and deployed a permanent software patch [2].
TechRadar Pro contributor Sead Fadilpašić reported that the threat actor leveraged remote command execution to extract sensitive Personal Information records and critical system credentials. Fadilpašić, writing from Sarajevo, Bosnia and Herzegovina, noted that the full operational fallout emerged only after engineers examined database transaction logs. Corporate leaders formally submitted an incident report to the Japan Personal Information Protection Commission on September 15. The official Breach Notice followed on Wednesday [1].
Server access ceased. However, stolen Personal Information had already reached external destinations before Customer Support defenses responded [1].
Compromised Credentials and Account Identifiers
The incident compromise involves approximately 23.62 million user records extracted from Gyazo’s databases. Corporate disclosures clarified that the total reflects raw database entries rather than distinct individuals, because single users frequently generate multiple records and millions of captures originate from anonymous accounts lacking registered emails. Compromised files include user names, nicknames, email addresses, cryptographic password hashes, unique User Identifier numbers, and physical Device Identifier records. Authentication records also revealed active login session IDs and language preferences registered during service interaction as the full scope of the Gyazo data breach became clear [2].
Beyond foundational account details, the compromised datasets contained sensitive external connection tokens for users who linked third-party platforms to their Gyazo accounts. Intruders obtained Twitter Integration tokens and email addresses utilized for Google Single Sign protocols (SSO, a federated authentication system linking external accounts) as well as complete registration and recent login timestamps. Subscription plan tiers and general usage statistics were also exposed, though Helpfeel explicitly verified that unauthorized parties obtained no payment card information or banking details. The exposure of persistent authentication tokens and session identifiers reflects broader industry vulnerabilities documented when secrets leaked across Android applications during credential extraction reviews. Stolen credentials elevate fraud risks [1, 2].

Gyazo Customer Support routinely issues email verification codes whenever account holders attempt logins from unrecognized network IP addresses. Nevertheless, Helpfeel has not clarified whether exposed session tokens remain active or whether security teams invalidated all outstanding cookies immediately following the breach. The Kyoto organization confirmed executing restrictive countermeasures across authentication systems, but specific revocation protocols remain undisclosed. Users must scrutinize incoming messages for phishing attempts [2].
Millions of Unguessable Image Links Exposed
In addition to account profiles, the threat actor exfiltrated approximately 490 million image metadata records created in or before January 2019. These historic records represent roughly 14.4% of all image-related data hosted across Helpfeel’s systems. A secondary collection containing metadata for 2.4 million captures was separately exfiltrated using specific filtering criteria that corporate investigators have not publicly defined. Leaked entries incorporate source upload IP addresses, client User Agent strings, image titles, and EXIF (metadata preserving geographic coordinates and camera parameters) information [1, 2].
Every Gyazo capture automatically receives a public web link constructed from a unique 32-character image identifier. Official documentation from the Customer Support portal assures users that default captures remain private until shared, explicitly advertising that the 32-character string cannot be guessed by third parties. Can unguessable URLs protect sensitive screenshots once database identifiers leak? Because the leaked metadata includes the exact image IDs required to construct full URLs, external actors can directly reconstruct active links to view stored captures without authorization [2].
The exposure also compromised extracted OCR (optical character recognition technology that transcribes text within pictures) data generated by Gyazo’s paid search utility. While marketing literature promises that OCR text remains visible only to account holders, database breaches bypass interface restrictions entirely. Furthermore, the attacker obtained hashed passphrases and administrative inventories identifying captures marked Only me. Helpfeel acknowledged that it cannot rule out the possibility that unauthorized third parties viewed confidential customer photographs during the Gyazo data breach. Viewing was disabled for select files [1, 2].

Disruption Timeline and Maintenance Notices
As corporate defenders struggled to isolate compromised servers between September 11 and September 14, regular Gyazo users encountered persistent image loading errors across web applications. Helpfeel initially attributed these operational outages to scheduled Emergency Maintenance procedures on Product Updates boards without disclosing the underlying intrusion. Disruptions spread rapidly. Delivery for selected images was suspended on September 14. When new uploads resumed on September 15, updated notices merely stated that specific images remained unavailable due to Emergency Maintenance procedures [2].
Helpfeel formally verified data exfiltration on September 14 following preliminary forensic reviews. The organization promptly informed Japanese regulatory authorities at the Personal Information Protection Commission on September 15 before releasing its public Breach Notice on September 16. External cybersecurity forensics specialists are currently conducting a comprehensive post-incident assessment to determine the full scope of exfiltrated assets. Independent verification remains ongoing [2].
Free tier accounts on Gyazo are ordinarily restricted to browsing their ten most recent captures on the service dashboard, yet older uploads permanently persist online for anyone possessing the URL. Will casual users realize that historic captures uploaded years ago might be compromised? Helpfeel stated that its enterprise software offerings, including Intelligent Search utilities and Cosense collaborative platforms, operate on distinct technical infrastructure. Forensic audits detected no evidence of compromise within those corporate software environments [2].
Protective Measures and Security Recommendations
Helpfeel instructed all registered Gyazo users to reset their account passwords immediately to mitigate unauthorized credential reuse. Users must change identical or similar passwords across any third-party online platforms sharing credentials with their Gyazo profiles. The Customer Support company announced plans to dispatch direct email warnings to confirmed victims while maintaining public advisories for anonymous uploaders. Communication channels remain active [2].
In cybersecurity evaluations published by TechRadar Pro, security journalist Sead Fadilpašić underscored that individuals facing credential compromises should deploy specialized endpoint protections to block incoming phishing attacks and credential stuffing. Fadilpašić, who previously reported on digital security and international legislation for Al Jazeera Balkans and conducted training modules for Represent Communications, highlighted commercial defense suites such as Bitdefender Total Security, McAfee Mobile Security, and Norton LifeLock offerings. Active monitoring protects accounts against automated intrusion scripts [1].
Subscribers holding private captures on Gyazo must immediately examine their stored image libraries and submit detailed inquiries through Gyazo’s official Support Form if they suspect proprietary records were viewed by unauthorized actors. Because image delivery remains suspended for specific historic captures while external specialists finalize their audit, account holders must audit their integration settings, revoke active application tokens, and verify that shared screenshot links contain no unencrypted personal identifiers. Taking immediate security precautions resolves lingering vulnerabilities following the Gyazo data breach [2].
- ONLINE NEWS Fadilpašić, S. (2026, September 17). Gyazo breach exposes 23.62 million user records and 490 million image records — PII and metadata exposed in huge attack. TechRadar. https://www.techradar.com/pro/security/gyazo-breach-exposes-23-62-million-user-records-and-490-million-image-records-pii-and-metadata-exposed-in-huge-attack [Article Link]
- ONLINE NEWS The Hacker News. (2026, September 17). Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records. The Hacker News. https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html [Article Link]