Gyazo, Helpfeel's image-sharing service, has disclosed a breach that exposed roughly 23.62 million user records β including email addresses, password hashes, user IDs, session IDs and X/Google SSO tokens where connected β and about 490 million image-metadata records, mostly for images registered in January 2019 or earlier. The attacker entered through a vulnerability in Gyazo's image upload server, ran arbitrary commands on Helpfeel's systems and accessed the database; Helpfeel reported the incident to Japan's Personal Information Protection Commission on 15 September and published its notice on 16 September. The population-relevant detail is the metadata exposure: image IDs that make up Gyazo image links can be used to view unencrypted captures without permission, and Helpfeel could not rule out that private images were viewed. It disabled viewing of some images and says no payment information was exposed, but the leaked records include OCR text and hashed passphrases for private images. The breach count reflects records, including anonymous accounts with no email; Helpfeel is still determining how many individuals are affected and is running an external forensic investigation, with notification of confirmed affected users via email.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-09-18 |
| Source | Helpfeel |
| Reliability | Tier 1 |