A data breach at the image-recording tool Gyazo, stemming from a server vulnerability, has exposed 23.62 million records. With over 3 billion uploads, HelpFeel’s Gyazo is a popular image-sharing platform among gamers and streamers.
The company learned of the data breach on September 11, 2026, after experiencing suspicious activity on its systems.
Upon detection, Gyazo launched an investigation with external cybersecurity experts and determined that an unauthorized third party had exploited its image upload server and executed arbitrary commands after deploying malware.
Gyazo data breach leaks 23.6 million records
According to a statement on its website, Gyazo says the attackers gained access to a user database and obtained user information for approximately 23.6 million people, as well as image metadata. Nevertheless, multiple records could belong to a single user, making it impossible to determine the total number of individuals affected.
“We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization,” HelpFeel stated.
The data breach exposed the victims’ names, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile information, language preferences, subscription plans, billing statuses, usage statistics, registration dates, and last logins.
However, the exposed information varied by individual and included data from anonymous accounts without linked email addresses. Additionally, the data breach did not expose payment information, including credit card details or bank account numbers.
The data breach also did not affect sister platforms HelpFeel and Cosense, which use a different infrastructure from Gyazo. The company also says it successfully terminated the threat actor’s access within hours.
“An image upload server that accepts arbitrary command execution is a fundamental misconfiguration, and the fact that it sat adjacent to a database holding half a billion metadata records tells you the internal segmentation was not there,” said Seemant Sehgal, Founder & CEO, BreachLock.
Meanwhile, Gyazo advises users to change their passwords, avoid reusing them, and watch for suspicious or unsolicited communications to help prevent phishing.
Additionally, Gyazo has notified Japan’s Personal Information Protection Commission and will directly contact impacted users via email and post data breach notices on its website for anonymous users who cannot be contacted directly.
At the time of publication, the image-sharing platform has not disclosed the nature of the exploited vulnerability or the identity of the threat actor. The company has also not disclosed receiving a ransom demand, and no cybercrime group has publicly taken responsibility for the cyber attack.
“Thankfully, none of the information exposed in this breach should pose a direct threat to breach victims’ finances or identities,” said Paul Bischoff, Consumer Privacy Advocate at Comparitech. “The passwords were hashed and thus cannot feasibly be reverted to plain text. HelpFeel is asking users to reset their passwords anyway, just in case. Email addresses and other identifying info could be used to craft convincing phishing messages for which victims should be on alert. Scammers might pose as Gyazo or a related company to trick victims into clicking on malicious links that lead to malware and scams.”
Gyazo data breach exposed sensitive image metadata
According to Gyazo, the data breach also exposed 490 million metadata records of images uploaded from January 2019 and earlier. The metadata records included image IDs used to construct image URLs, source IP addresses, user-agent strings, EXIF location data (if present), OCR text extracted from the image, image titles, source URLs, and hashed passphrases for private captures.
Attackers and other entities could weaponize EXIF location data, OCR text, and IP addresses to target impacted users via phishing, malware delivery, account takeover attempts, and even physical stalking.
“The exposure most people will focus on is the 23 million user accounts, but the metadata layer is where the real reach is,” added Sehgal. “EXIF coordinates, OCR-extracted text, session IDs, and image URL construction data give an attacker enough to reconstruct user behavior and location history for tens of millions of people who uploaded a screenshot and never thought about it again.”
To protect users, Gyazo disabled image uploading and viewing to prevent unauthorized access and took the system offline until September 15. The company also says it has taken additional measures to protect user information from misuse, including “invalidation and restrictions.”
While Gyazo believes that private images, which are available only on the paid plan, may have been viewed, the company has no evidence of data loss.
“As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation,” Gyazo explained.

