Data Breach

Gyazo breach exposes 23.6M users and 490M image records

⏱️ 3 min read📅 9/18/2026👁️ 15 views

What happened

23.6 million Gyazo users had their personal data accessed in a single breach. Helpfeel, the company behind Gyazo, discovered the intrusion on September 12, 2026, after it started the day before.

The attacker exploited a flaw in the image‑upload service, gained read access to the user database, and was evicted a day later.

Why it matters

The stolen records contain names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics, and billing information. While payment‑card numbers were not reported as taken, the breadth of data gives attackers plenty of leverage for credential stuffing, phishing, or extortion.

Technical snapshot

The breach centered on Gyazo’s image‑upload server. The exact CVE was not disclosed, but the fact that a single vulnerable component exposed both user tables and 490 million image‑metadata rows shows a serious lack of segmentation.

  • ~23.6 million user records accessed
  • ~490 million image‑metadata entries accessed
  • Private image list compromised (volume unknown)

Who’s affected

Anyone with a Gyazo account – free or paid – is potentially in the cross‑hairs. The data set includes both registered users and anonymous accounts, though the split is unclear.

What you can do now

  1. Assume your Gyazo password is compromised; change it immediately and use a unique, strong password.
  2. Enable two‑factor authentication on Gyazo and any linked services (e.g., X).
  3. Monitor email for suspicious login attempts or phishing messages that reference Gyazo data.
  4. Consider using a password‑manager to generate new credentials and audit reused passwords.
  5. For businesses that embedded Gyazo, review integration tokens and rotate them.
#Gyazo#data breach#image sharing#Japan#user data#security incident