Helpfeel Inc., the Kyoto-based company behind the screenshot tool Gyazo, has confirmed a breach affecting roughly 23.62 million user accounts and exposing metadata for over 490 million images.
Gyazo isn’t just a casual image host. Developers, IT staff, and gamers use it daily to share debugging logs, code snippets, private messages, and infrastructure diagrams. That’s what makes the exposed metadata — OCR text and image routing IDs in particular — dangerous well beyond the usual phishing and credential-stuffing risk. It hands an attacker a searchable window into years of screenshots people assumed were private.
How the intrusion happened
According to Helpfeel’s disclosure on September 16, 2026, the attacker didn’t go after an employee or run a phishing campaign. They went after the image upload server directly, exploiting an undisclosed vulnerability to execute arbitrary commands on Helpfeel’s backend systems. That kind of flaw, whether it comes from remote code execution, insecure deserialization, or bad file-parameter handling, means the server processing untrusted uploads from millions of users didn’t have the sandboxing it needed.
From there, the attacker moved laterally into Gyazo’s primary database. That points to a network segmentation problem: the public-facing upload servers apparently had more access to backend data than they should have.
Timeline, and the maintenance cover story
- September 11 (late evening JST): Helpfeel detects suspicious activity and starts investigating.
- September 12 (early hours): The company blocks the access routes, cuts the attacker off, and patches the vulnerability.
- September 14: Forensics confirm unauthorized data disclosure. Image delivery is suspended.
- September 15: Uploads resume, and the breach is reported to Japan’s Personal Information Protection Commission.
- September 16: The public notice goes out.
Between September 12 and 15, users hitting broken embeds or old images saw generic “emergency maintenance” notices. Keeping quiet during containment to avoid tipping off an active attacker is standard practice. But labeling a confirmed database exfiltration as routine maintenance also delayed the moment users could start rotating passwords and revoking tokens.
What was actually exposed
The breach splits into two categories: user account records and image metadata. The 23.62 million compromised accounts are a serious problem on their own. The 490 million metadata records are, in some ways, the harder one to contain.
User accounts (23.62 million)
Helpfeel says no credit card or payment data was exposed. What was: email addresses, usernames, language preferences, password hashes, user and device IDs, and login session IDs. Also exposed were X (formerly Twitter) integration tokens and the email addresses tied to Google SSO logins, along with registration dates, last login times, subscription tiers, and usage stats.
The password hashes are the first problem — if Gyazo used weak hashing (unsalted MD5, SHA-1, or a low bcrypt cost factor), a lot of those passwords could be cracked within days, feeding credential-stuffing attacks across other sites. The session IDs are arguably worse: with an active session ID, an attacker can potentially hijack an account without ever needing the password. And the leaked OAuth tokens for X and Google SSO open the door to account takeovers on other platforms too, depending on what permissions those tokens carried.
Image metadata and the end of “unguessable” URLs
Gyazo’s privacy model has always rested on obscurity: every capture gets a 32-character random ID, and the company has long said that ID is effectively unguessable. The breach undercuts that. The attacker now has the database of Image IDs — the directory that maps to hundreds of millions of files people assumed were private.
Most of the exposed metadata, about 490 million records, covers images uploaded in or before January 2019, roughly 14.4% of Helpfeel’s total image data. A separate set of 2.4 million records was pulled using what Helpfeel calls “specific filtering criteria” that the company hasn’t explained yet — which raises the question of whether the attacker was targeting enterprise domains or particular regions.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Because the ID is the only thing standing between an attacker and a private image, having the ID database means the attacker can construct valid URLs and pull the actual files at will. Helpfeel has acknowledged this directly, saying it can’t rule out that private images were viewed, and has disabled viewing for affected subsets in the meantime — which is why embeds are breaking across the web right now.
The OCR problem
The metadata leak also includes source IP addresses, user-agent strings, EXIF location data, and OCR text — and the OCR piece is the one that should worry security teams most.
Gyazo Pro runs OCR on uploaded images so users can search their screenshot history by keyword. It’s a popular feature among developers and IT staff, which is exactly the problem: plenty of screenshots capture terminal windows with exposed AWS keys, Slack messages with 2FA bypass codes, proprietary code, or Jira tickets describing an unpatched vulnerability. All of that text was stored searchable in the database, and now it’s in the attacker’s hands too.
Running regex across that dataset would surface things like AWS secret keys, RSA private key headers, internal IP ranges and subnet maps, and passwords that got captured accidentally in a screenshot.
The EXIF location data adds another angle — it can be used to map where enterprise employees or developers physically are. And Gyazo Pro’s password-protected images had their passphrase hashes exposed too, so if that hashing was weak, those “private” repositories aren’t private anymore either.
Ripple effects across Helpfeel’s other products
Helpfeel also runs Helpfeel and Cosense, its knowledge-management tools, and says those run on separate infrastructure with no direct exposure. That’s true at the database level, but both products lean heavily on embedded Gyazo images for documentation and internal wikis. With Helpfeel blocking delivery of legacy images to prevent scraping, a lot of internal docs and support tickets are now showing broken images.
What to do about it
“Change your password” doesn’t cover a breach that includes session tokens, SSO links, and searchable OCR text. Here’s what actually matters.
If you’re an individual user:
- Change your Gyazo password, and change it anywhere else you reused it. Treat the hashes as already under attack.
- Revoke Gyazo’s access in your Google account security settings and X app permissions. This kills the stolen tokens and forces re-authentication.
- Go through your older screenshots, especially anything from before 2019, and delete ones with passwords, API keys, or sensitive info. The metadata’s already gone, but deleting the file stops anyone from pulling the image itself via the leaked ID.
- Watch for phishing that uses your leaked device ID or registration date to look convincing — expect “Gyazo security alert” emails built around real details.
If you’re running IT or security for a team:
- Assume anything sensitive your team screenshotted and uploaded to Gyazo — API keys, credentials, infrastructure details — is now searchable by an outside party. Rotate what needs rotating.
- Check your identity provider logs for odd Gyazo login activity, and force a session logout across the org to kill any hijacked sessions.
- Audit Notion, Confluence, Cosense, and other internal docs for broken Gyazo embeds, and replace critical ones with locally hosted, access-controlled images.
- Reconsider letting an unmanaged, consumer screenshot tool touch corporate workflows at all. This is the kind of breach that argues for enterprise tools with real DLP controls instead.
The bigger issue
This breach comes down to Helpfeel holding onto more data than it needed, protected by a scheme — unguessable URLs — that was never as strong as it sounded. Keeping OCR text, metadata, and image IDs going back over a decade turned Gyazo into a huge, centralized store of contextual user data, and once someone got in, that data was all sitting there waiting.
Helpfeel’s technical response was fast: they cut off the attacker within hours of detecting the intrusion on September 12. But the delay in telling the public, combined with how much legacy data was sitting around to be taken, is what turned this into the mess it is now. Whether the attacker tries to sell the OCR dataset on dark web forums, or whether the leaked Image IDs lead to mass scraping of years of private screenshots, is still an open question.
Until Helpfeel explains exactly what the upload server vulnerability was and what “specific filtering criteria” pulled that second batch of 2.4 million records, this should be treated as a full compromise of Gyazo’s privacy model — not a partial one.










“the public-facing upload servers apparently had more access to backend data than they should have.” Gee, where have we heard that before?
News like these will only increase due to more reliance on AI. Vibecoded