23M user records compromised in Gyazo data breach

Summary

Gyazo experienced a significant data breach affecting 23 million user records after attackers exploited a vulnerability in the company's image upload server on September 11, 2026. The breach exposed user account details, including emails and password hashes, along with image metadata that could enable the reconstruction of shareable links. In response, Gyazo has released a detailed breach notice, reported the incident to regulators, and advised users to update their passwords while implementing measures to safeguard compromised content.

Analysis

Gyazo: Gyazo is an image-sharing service operated by Japanese company Helpfeel that enables users to capture and instantly share screenshots, GIFs, and short screen recordings via unique links. The platform was targeted in a September 2026 cyberattack in which a third party exploited a vulnerability in its image upload server to gain unauthorized access to systems and data. Helpfeel has publicly disclosed the incident, notified users, and implemented protective measures including temporary service adjustments. Company Response: Helpfeel has published a detailed breach notice, reported the incident to regulators, and advised users to update passwords while taking steps to protect affected content. Incident Timeline: Attackers gained access to Gyazo systems on September 11, 2026, by exploiting a vulnerability in the image upload server, with the company detecting and blocking the activity shortly thereafter. Data Exposure Type: The breach involved user account details such as emails and password hashes along with image metadata that could potentially allow reconstruction of shareable links.

Categories

tech

Related sources

View Original Tweet