
Helpfeel, the Kyoto-based company behind the Gyazo screenshot-sharing service, disclosed a data breach that exposed roughly 23.62 million user records and metadata for 490 million images. The exposed user records can include email addresses, password hashes, usernames, account IDs, and in some cases OCR text — text that Gyazo extracted from users’ captured screenshots. No payment information or credit card numbers were exposed. The attacker accessed Gyazo’s database by exploiting a vulnerability in the image upload server, running arbitrary commands on Helpfeel’s systems. The company noticed suspicious activity on September 11, blocked the attacker’s access routes by September 12, and confirmed on September 14 that data had been exfiltrated.
The 490 million metadata records are especially notable because they include the unique 32-character image IDs that form Gyazo’s image links — links that normally act as the only privacy protection for captures set to the default “anyone with the link can view” setting. Helpfeel has temporarily disabled viewing of some images to limit further exposure. The company said private images (set to “Only me” or password-locked, available on paid plans) may also have been accessed. Helpfeel is asking all users to change their Gyazo password and to update any other service where the same password was used.
How to check if you’re affected
Affected products include all Gyazo user accounts — the breach covers 23.62 million records, and the company is still working out exactly how many people had personal information exposed. If you have a Gyazo account, change your password immediately and update it anywhere else you reused it. Check your email for a notification from Helpfeel, and watch for suspicious messages referencing images you may have captured. If you have older images that you considered private (pre-2019 especially), assume their image IDs are now known to the attacker.
