• 4 min read
Gyazo breach exposed 490 million image records
Helpfeel says an attacker accessed 23.62 million Gyazo records and metadata for roughly 490 million images, and private images may have been viewed.

Image: TechRadar
A September 11, 2026 intrusion at Helpfeel, operator of the Gyazo image-sharing service, exposed 23.62 million user-related records and roughly 490 million image-metadata records. The account dataset includes password hashes, session identifiers and third-party tokens; the image dataset can contain upload IP addresses, location data, OCR-extracted text and information used to construct image URLs.
Helpfeel says the attacker exploited a vulnerability to upload malware to its servers, then used that foothold to execute arbitrary commands. The company has not identified the attacker or specified the vulnerable component in the material available so far.
The two figures measure records, not confirmed victims. Helpfeel says multiple records can belong to one person, while many entries were generated by people who used Gyazo without creating accounts. As a result, 23.62 million is not the number of individuals affected, and the company has not yet published an estimate for that population.
Account data includes hashes, sessions and SSO identifiers
The exposed user-record set includes names, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google single-sign-on email addresses, profile information, language preferences, registration and login timestamps, subscription-plan information, billing status, and usage statistics.

Recommended reading
Vite scans hit 32,000 events chasing AWS and Azure secrets
Sergey Kuznetsov • • 4 min read
Password hashes are not the same thing as plaintext passwords, but their exposure still matters, particularly for people who reuse credentials across services. Session IDs and integration tokens are access-related identifiers, not merely historical account fields. Helpfeel has not said whether the exposed session IDs or tokens were active, expired, revoked, or otherwise unusable at the time of the breach.
The company said payment data was outside the compromised material.
“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization.”
| Exposed record group | Reported volume | Fields Helpfeel says were included |
|---|---|---|
| Gyazo user-related records | 23.62 million | Names, email addresses, password hashes, IDs, session IDs, X tokens, Google SSO email addresses, account and usage data |
| Image metadata records | Approximately 490 million | Image IDs, upload IP addresses, user agents, EXIF location data, OCR text, titles, source URLs and hashed private-image passphrases |
The image figure is constrained in a way the user-record figure is not: Helpfeel says it covers images registered in or before January 2019. The disclosure does not establish that every Gyazo image or every current account was exposed, nor does it put a number on potentially affected private images.
Image metadata included location and OCR data
For the image records, the distinction is between the image file itself and the information stored alongside it. Helpfeel says the stolen metadata included EXIF location information, text extracted through optical character recognition, upload IP addresses, browser user-agent strings, image titles and source URLs. Those fields may reveal location, words contained in an image, how it was uploaded, and where it originated even if the image itself was not directly copied.
Helpfeel also says the metadata included hashed passphrases for private images. It acknowledges that some exposed metadata is used to generate image URLs, so it cannot exclude the possibility that the intruder retrieved the underlying files, including files intended to be private.
“We have temporarily disabled viewing of some images to prevent further harm.”
“As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”
Temporarily disabling access to some images is a containment measure, not confirmation of what was accessed. Helpfeel has not said how many image views it disabled, which image classes were affected, whether stolen URL-generation data could be used elsewhere, or whether it has detected any use of exposed account tokens or session identifiers.
The disclosure follows other 2026 data incidents
The Gyazo incident joins 2026 disclosures in which companies said financial data was not exposed while acknowledging the loss of identity, contact, or behavioral data. In August, France said a breach exposed tax, business and cadastral data connected to 678,000 people and companies in France’s tax-authority breach. Framework also said customer contact and address data, but not payment information, had been exposed in its Metabase breach.
Manchester Airports Group’s August disclosure said data tied to up to 8.7 million customers had been stolen across Manchester, Stansted and East Midlands airports. That incident involved contact details, postcodes and vehicle registrations. The Gyazo disclosure combines account identifiers with image-linked metadata and a stated possibility that private visual material was viewed.
| Incident | Date disclosed | Reported exposure |
|---|---|---|
| Gyazo / Helpfeel | September 2026 | 23.62 million user-related records; approximately 490 million image-metadata records |
| France tax authority | August 17, 2026 | Data linked to 678,000 people and companies |
| Manchester Airports Group | August 29, 2026 | Data connected to up to 8.7 million customers |
For Gyazo users, the unanswered details are whether their account record was in the affected set, whether any tokens or sessions remained usable, and whether a private image was retrieved rather than merely represented by metadata. Helpfeel has confirmed none of those points at an individual level yet.
Frequently asked questions
How many Gyazo users were affected?+
Helpfeel says 23.62 million user-related records were compromised, but that is not a count of people. Multiple records may belong to one user, and some were generated by people without accounts.
Were Gyazo private images exposed?+
Helpfeel says it cannot rule out that some private images were viewed because compromised metadata may be used to generate image URLs. Its investigation is ongoing.
Did the Gyazo breach expose credit card numbers?+
No. Helpfeel says no payment information, including credit card numbers, was disclosed without authorization.
What data was exposed in the Gyazo breach?+
The disclosed categories include names, email addresses, password hashes, session IDs, X tokens, Google SSO email addresses, account data, and image metadata such as IP addresses, EXIF location data and OCR text.
Editor-in-Chief
Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.


