01Summary
Kyoto-based Helpfeel said an attacker broke in on 11 September 2026 through a vulnerability in Gyazo's upload server, gained remote code execution and accessed databases of account records and image metadata. Access was cut off on 12 September and the breach disclosed on 16 September. Exposed data includes names, emails, password hashes, user, device and session IDs, OCR-extracted text from screenshots, EXIF location data, X/Twitter integration tokens, Google SSO profile data and billing information (no card numbers). Helpfeel reported the incident to Japan's Personal Information Protection Commission.
02Key revelations
- 01Text extracted from users' screenshots by OCR was stored and exposed.
03Technical analysis
- Attack vector
- Vulnerable public-facing upload server
- Attack method
- Remote code execution leading to database access
- Initial access
- Exploitation of a public-facing application
04Victims and impact
Countries affected
- Japan
- Global
05Data exposed
Data types
- Names
- Email addresses
- Password hashes
- OCR text from screenshots
- EXIF location data
- Third-party OAuth tokens
- Billing information
06Timeline
- 2026-09-11Intrusion begins.
- 2026-09-12Access terminated.
- 2026-09-16Helpfeel discloses the breach.
07Legal
Reported to Japan's Personal Information Protection Commission.
08Disclosure and media
Publishing organisations
- Tech Insider
09Field notes
- 01About 490 million image metadata records were accessed, roughly 20 per user.
10Sources
References
- [1]Tech Insider: https://tech-insider.org/gyazo-data-breach-23-6-million-users-2026/









