EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-gyazo-helpfeel-breach
005/430

File EL-0426HighContainedData Breach / Remote Code Execution / Database Theft

Gyazo Data Breach

Also filed as Helpfeel Gyazo Hack

An attacker exploited a flaw in Gyazo's image upload server to run code and steal about 23.6 million user records and about 490 million image metadata records.

  • #japan
  • #screenshots
  • #password-hashes
  • #location-data
  • #saas
Notoriety8/10
Event
11 Sept 2026
Disclosed
16 Sept 2026
Target
Helpfeel (Gyazo)
Scale
23.6M people
Status
Contained

01Summary

Kyoto-based Helpfeel said an attacker broke in on 11 September 2026 through a vulnerability in Gyazo's upload server, gained remote code execution and accessed databases of account records and image metadata. Access was cut off on 12 September and the breach disclosed on 16 September. Exposed data includes names, emails, password hashes, user, device and session IDs, OCR-extracted text from screenshots, EXIF location data, X/Twitter integration tokens, Google SSO profile data and billing information (no card numbers). Helpfeel reported the incident to Japan's Personal Information Protection Commission.

02Key revelations

  1. 01Text extracted from users' screenshots by OCR was stored and exposed.

03Technical analysis

Attack vector
Vulnerable public-facing upload server
Attack method
Remote code execution leading to database access
Initial access
Exploitation of a public-facing application

04Victims and impact

Countries affected

  • Japan
  • Global

05Data exposed

Data types

  • Names
  • Email addresses
  • Password hashes
  • OCR text from screenshots
  • EXIF location data
  • Third-party OAuth tokens
  • Billing information

06Timeline

  1. 2026-09-11Intrusion begins.
  2. 2026-09-12Access terminated.
  3. 2026-09-16Helpfeel discloses the breach.

07Legal

Reported to Japan's Personal Information Protection Commission.

08Disclosure and media

Publishing organisations

  • Tech Insider

09Field notes

  1. 01About 490 million image metadata records were accessed, roughly 20 per user.

10Sources

References

  1. [1]Tech Insider: https://tech-insider.org/gyazo-data-breach-23-6-million-users-2026/
Fact sheetEL-0426

Dates

Event
11 Sept 2026
Started
11 Sept 2026
Ended
12 Sept 2026
Duration
2 days
Discovered
12 Sept 2026
Disclosed
16 Sept 2026
Ongoing
No

Target

Organisation
Helpfeel Inc. — Gyazo image-sharing service
Type
Software / SaaS Company
Sector
Technology
Country
Japan

Actor

Arrested
No
Convicted
No

Data

People
23,620,000
Records
23,620,000
Sensitivity
High

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.