Skip to content
Gyazo Breach Exposes 23.62 Million User Records

Gyazo Breach Exposes 23.62 Million User Records

First seen 17 Sep 2026, 14:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 16:32 UTC
  • 23.62 million user records and 490 million image metadata records exposed.
  • Attackers exploited a vulnerability in Gyazo's image upload server.
  • Users advised to change passwords and monitor for suspicious activity.

Helpfeel Inc. confirmed a security breach at Gyazo, its image-sharing service, which exposed approximately 23.62 million user records and 490 million image metadata records. The breach occurred on September 11, 2026, when a third party exploited a vulnerability in Gyazo's image upload server, allowing unauthorized access to the database. The exposed user data includes names, email addresses, and integration tokens, but no payment information was compromised. Helpfeel has blocked the access routes used in the attack and is investigating the incident's scope and impact. Users are advised to change their passwords and monitor for suspicious communications. The investigation is ongoing, and further details may emerge.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
Breach occurred
A third party exploited a vulnerability in Gyazo's image upload server, gaining unauthorized access.
Helpfeel Inc.
2026-09-12
Suspicious activity detected
Gyazo detected suspicious activity and began investigating the incident, blocking identified access routes.
Helpfeel Inc.
2026-09-17
Public disclosure
Helpfeel publicly disclosed the breach, confirming the exposure of user records and metadata.
The Hacker News

More articles in this cluster (3)

Following this threat?

Track Cosense in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed