Gyazo hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Gyazo suffered a security breach that exposed 23.62 million user records and 490 million image metadata records, creating risk of unauthorized image access and credential abuse. The compromise came through a vulnerability in Gyazo's image upload server, and the attacker used that foothold to run arbitrary commands on Helpfeel's systems. Exposed records included email addresses, password hashes, session-related data, and image-link IDs that could let outsiders view captures without permission. Helpfeel disabled viewing for some images, told users to change passwords, and said the flaw was fixed after suspicious activity was noticed on September 11.
Related Happenings
GSS VPN device access security flaw
Vulnerability
H score54
First: 14.09.2026 23:36
Last: 14.09.2026 23:36
Sources 1
About this happening:
Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system...
GSS VPN device access security flaw
VulnerabilityAbout this happening: Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system...
Timeline
-
17.09.2026 10:30 1 articles · 7h ago
Helpfeel detects suspicious activity on Gyazo systems
Detection Ioc UpdateHelpfeel noticed suspicious activity on Gyazo systems on the evening of September 11, Japan time, indicating unauthorized access to the image-sharing service.
Show sources
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records — thehackernews.com — 17.09.2026 10:30
-
17.09.2026 10:30 1 articles · 7h ago
Helpfeel blocks attacker access and fixes the Gyazo vulnerability
Mitigation Patch UpdateBy the early hours of September 12, Helpfeel had blocked the access routes it identified, cut the attacker's connections, and fixed the vulnerability in Gyazo's image upload server.
Show sources
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records — thehackernews.com — 17.09.2026 10:30
-
16.09.2026 03:00 2 articles · 1d ago
Helpfeel confirms Gyazo data exposure and restricts image viewing
Initial DisclosureHelpfeel confirmed on September 14 that Gyazo data had been exposed, reported the incident to Japan's Personal Information Protection Commission on September 15, and published its notice on September 16. The company said some image viewing had been temporarily disabled, warned users to change their passwords, and stated that about 23.62 million user records and about 490 million image metadata records were exposed.
Show sources
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records — thehackernews.com — 17.09.2026 10:30
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records — thehackernews.com — 17.09.2026 10:30