Helpfeel, the Japanese company behind the popular screenshot and screen-recording platform Gyazo, has confirmed a data breach that exposed approximately 23.62 million user records after attackers exploited a vulnerability in its image upload server.
Gyazo lets users capture screenshots, GIFs, and short screen recordings and instantly generate shareable links, a feature widely used in gaming communities and online forums. The service claims 23 million users worldwide who have collectively submitted 3.1 billion media items.
According to Helpfeel, a hacker exploited the server flaw on September 11, 2026, enabling them to execute malicious commands and gain access to the company’s database. The intruder was locked out the following day after Helpfeel detected the suspicious activity, but not before exfiltrating a substantial amount of data.
What Was Exposed
The compromised records vary by user but may include names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, and usage statistics. Helpfeel says payment card information was not affected.
The dataset also includes records tied to anonymous accounts that never registered an email address, and the company says it is still working to determine the actual number of individuals impacted.
Beyond user records, the attacker accessed roughly 490 million image metadata records, most tied to images uploaded before January 2019. This metadata includes image IDs that can be used to construct image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images.
Because image IDs can potentially be used to access the underlying content, Helpfeel has temporarily disabled access to files tied to the exposed records. The company also confirmed that attackers obtained a list identifying private images and said it cannot rule out that some were viewed.
Response and Recommendations
Gyazo has been taken offline for maintenance as a precautionary measure while the investigation continues. Helpfeel says it found no evidence that data was deleted as a result of the incident, and no indication that its other Helpfeel or Cosense services were affected.
The company is notifying affected users directly, working with external experts, and has contacted authorities. Helpfeel is urging all Gyazo users to change their passwords on the service and on any other platforms where they reused the same credentials, and to remain alert for phishing attempts or other suspicious communications referencing the breach.
