CSIDB logo
Incident

Helpfeel

Incident posture

Attack window
Sep 2026
Location
Japan
Status
Unknown
CIA posture
Available to members
Updated
2026-09-20 07:09

Linked entities

Victim
Helpfeel
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Undetermined
Disclosed
Sep 2026
Resolved
Pending

Summary

Helpfeel disclosed that attackers exploited a vulnerability in the Gyazo image upload server to gain unauthorized access, remaining inside until they were removed shortly thereafter. The breach exposed approximately 23.6 million user records containing names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics and billing information, while payment card data was not compromised. In addition, the intruders accessed roughly 490 million image metadata records and a set of private images, though the volume of the latter was not disclosed.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Helpfeel, the Japanese software company behind the Gyazo image‑sharing service, announced that it detected unauthorized access to its Gyazo servers. The intrusion began when a hacker exploited a vulnerability in the image upload server on September 11, which allowed the execution of malicious commands. Although the attacker was removed from the system the following day, September 12, the breach had already persisted long enough to reach a database containing user information. According to Helpfeel, the compromised database held roughly 23.6 million user records. The company noted that this figure includes anonymous accounts that lack registered email addresses or other identifiable details. Helpfeel stated that it is continuing to determine the exact number of individuals whose personal information was disclosed without authorization.

The accessed user data comprised names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing information, while payment card details were not affected. In addition to the user records, the intruder obtained approximately 490 million image metadata records, which contain information that could be used to reconstruct and access the URLs of images uploaded by users. Helpfeel also disclosed that a list of private images had been compromised, although it did not provide any specifics on the volume of those images. As part of its response, the company began notifying affected users about the breach. Helpfeel indicated that it is working to assess the full scope of the impact and to secure its systems against further unauthorized access. The firm emphasized that it will continue to monitor the situation and provide updates as more information becomes available.

Sources

Sources available to members: 1 source.

CSIDB