23 Million User Records Compromised in Gyazo Data Breach

https://www.securityweek.com/wp-content/uploads/2026/09/image-file-photo-sharing.jpeg

Japanese software company Helpfeel is notifying users of its Gyazo image-sharing service that hackers have accessed their information.

Gyazo is a widely used cross-platform tool that lets users capture screenshots, GIFs, or short screen recordings and instantly generate shareable links.

Helpfeel revealed this week that it recently detected unauthorized access to Gyazo servers. A hacker exploited a vulnerability in its image upload server on September 11, enabling them to execute malicious commands.

The attacker was kicked out the next day, but not before accessing a database storing roughly 23.6 million user records.

The compromised Gyazo user information includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing information.

Payment card information was not compromised, according to the vendor.

Advertisement. Scroll to continue reading.

“The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more