Gyazo Data Breach Exposes 23.62 Million User Records: What Users Should Do
Gyazo owner Helpfeel says approximately 23.62 million user-related records were exposed after an attacker breached its image-upload server. Here’s what happened and the steps users should take.
Gyazo owner Helpfeel has disclosed a major data breach affecting approximately 23.62 million user-related records after an attacker exploited a vulnerability in the image-sharing service’s upload infrastructure.
The company said the unauthorised access began on 11 September 2026. Helpfeel detected suspicious activity that evening and, by the early hours of 12 September, said it had blocked the identified access routes and terminated the attacker’s connections.
Its investigation later found that the attacker had accessed Gyazo’s database and that user information, along with some metadata associated with uploaded images, had been disclosed without authorisation.
What data was exposed in the Gyazo breach?
According to Helpfeel’s 16 September security notice, the approximately 23.62 million affected records include anonymous accounts as well as registered users. The types of information involved vary by account.
The company says potentially exposed fields include names or nicknames, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens where connected, Google SSO-associated email addresses, profile information, language preferences, registration and last-login timestamps, subscription-plan information, billing status and usage statistics.
Helpfeel said the billing-status information does not include credit-card numbers or other payment-method details.
The disclosure does not mean every affected record contained every listed field. Helpfeel says its investigation is continuing and the scope could be refined as more information becomes available.
How did the breach happen?
Helpfeel says a third party exploited a vulnerability in Gyazo’s image-upload server and gained the ability to execute arbitrary commands. The company has not publicly attributed the intrusion to a named attacker.
After detecting the incident, Helpfeel says it blocked the access routes used in the attack and remediated the exploited vulnerability. It subsequently implemented additional measures intended to limit further harm.
On 14 September, the company temporarily suspended image delivery as a precaution while it continued investigating. It later resumed delivery of newly uploaded images after implementing response measures.
Are Helpfeel and Cosense affected?
In a further update dated 18 September 2026, Helpfeel said its Helpfeel and Cosense services use different system architectures from Gyazo and are not connected to the intrusion route used in the attack.
The company said its investigation had found no confirmed information leakage from Helpfeel or Cosense systems and no evidence of unauthorised access or attacks against those services. It nevertheless began an emergency security review as a precaution.
What Gyazo users should do now
Users should treat the incident as a reason to review account security, particularly because the disclosed dataset can include email addresses, password hashes, session identifiers and connected-account tokens.
- Change your Gyazo password if you have not already done so, especially if it was reused elsewhere.
- Change reused passwords on other services. A unique password for every important account reduces the impact of one service being compromised.
- Review connected accounts. If you linked Gyazo with X or another identity provider, check active sessions and authorised applications and revoke anything you do not recognise.
- Watch for phishing attempts. Attackers may use exposed names or email addresses to make fraudulent messages appear more convincing. Do not trust a message merely because it contains information associated with your account.
- Be cautious with unexpected password-reset or login messages. Navigate directly to the service rather than following suspicious links.
Helpfeel specifically advised users to remain vigilant for suspicious emails, messages and other communications related to the incident.
Why password hashes still matter
A password hash is not the same thing as a plain-text password. Properly designed systems store passwords in transformed form rather than directly. However, disclosure of password hashes can still create risk, particularly when weak or reused passwords are involved. That is why changing a potentially affected password — and any identical password used elsewhere — remains a sensible precaution.
What happens next?
Helpfeel says the investigation remains ongoing. That means the confirmed number of records, the precise data involved and the broader impact could be updated as the investigation progresses.
Users should therefore rely on Helpfeel’s official security notices for subsequent technical findings or account-specific instructions.
For broader context on why account-data exposure can matter, FlyingEze has previously covered a separate website security issue involving exposed customer account data .
Bottom line
The confirmed facts are significant: Helpfeel says an attacker breached Gyazo’s upload infrastructure, accessed its database and caused the unauthorised disclosure of approximately 23.62 million user-related records. The company says it has closed the identified intrusion route and taken further precautions, but its investigation is not yet finished.
For users, the practical priority is straightforward: secure the Gyazo account, replace any reused password, review connected services and remain alert to phishing or unexpected account activity.