Skip to content
TrustList
News

Helpfeel says Gyazo breach exposed 23.62 million user records and screenshot text

Editorial

By TrustList Editorial

Helpfeel said on 16 September that attackers exploiting a Gyazo upload server took about 23.62m user records and about 490m image metadata records, including OCR text. Firms whose staff use Gyazo should reset passwords and review screenshots.

About Helpfeel says Gyazo breach exposed 23.62 million user records and screenshot text

Helpfeel says Gyazo breach exposed 23.62 million user records and screenshot text

22 September 2026 — Helpfeel, the Kyoto-based company that runs the screenshot-sharing service Gyazo, disclosed on 16 September 2026 that a third party had exploited a vulnerability in Gyazo's image upload server on 11 September, run commands on its systems and taken data from its database. Helpfeel says about 23.62 million user records and about 490 million image metadata records were disclosed without authorisation.

What Helpfeel says was taken

The user records vary by user but can include name or nickname, email address, password hash, user and device IDs, login session IDs, an X (formerly Twitter) integration token where connected, the email address linked to Google sign-in where used, profile details, subscription plan, billing status and usage statistics. Helpfeel says no card numbers or other payment details were taken, and that the total includes anonymous accounts with no email address, so the number of people affected is still being worked out. It says it has invalidated or restricted the authentication data involved. It does not name the password hashing method.

The image metadata relates mainly to images uploaded in or before January 2019, about 14.4% of all image data, plus metadata for about 2.4 million images pulled out using specific filters. It includes the image IDs used to build image URLs, uploaders' IP addresses, user agents, EXIF location where present, text extracted from images by OCR, titles, source URLs and hashed passphrases for private images. Helpfeel says the attacker also obtained a list identifying private images and that it cannot rule out some private images having been viewed. It has temporarily blocked viewing of some images, and says it has found no loss of image data.

Helpfeel's timeline: suspicious activity detected on the evening of 11 September; access routes blocked early on 12 September; theft of data confirmed on 14 September; a report made to Japan's Personal Information Protection Commission on 15 September. A follow-up on 18 September said no access to its separate Helpfeel and Cosense products had been found. BleepingComputer's report of 18 September rests on Helpfeel's notice.

Why it matters for businesses

Screenshots often capture internal dashboards, customer records, error messages with keys, or chat threads. For the affected records, the text read from those images is now outside Helpfeel's control even where the image itself was not taken, and image IDs could let someone open the pictures.

What to do

  • Find out who in your organisation uses Gyazo, through its desktop app or browser extension, and whether on personal or company accounts.
  • Have users change their Gyazo password and any matching password used elsewhere, as Helpfeel asks.
  • Remove Gyazo from connected apps in X, and review third-party access on any Google account used to sign in to Gyazo.
  • Assess what staff captured with Gyazo, especially before 2019. If screenshots showed passwords, API keys, customer data or internal systems, rotate those secrets and consider whether a data protection assessment or notification is needed.
  • Treat private Gyazo links as potentially exposed and delete sensitive images you no longer need.
  • Warn staff about phishing that uses the breach as a lure.
  • Decide whether Gyazo stays on your approved-tools list.

What is still unknown

Helpfeel has not said how the attacker got in beyond an upload-server flaw, who was behind it, or how many individuals are affected. It says its investigation, with outside specialists, continues.

Sources