CSIDB logo
Incident

Gyazo

Incident posture

Attack window
Sep 2026
Location
Japan
Status
Unknown
CIA posture
Available to members
Updated
2026-09-24 19:17

Linked entities

Victim
Gyazo
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Gyazo suffered a breach when an attacker exploited a vulnerability in its image upload server, gaining remote code execution and accessing a database that contained approximately 23.6 million user records and about 490 million image metadata records. The exposed data included names, email addresses, password hashes, user and device IDs, login session IDs, billing information, X integration tokens, Google single sign‑on data, image IDs, OCR‑extracted text, and EXIF location data, while payment card details were not compromised. The attacker was removed the following day, and the company disclosed the incident several days later after notifying Japan’s Personal Information Protection Commission.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 11, 2026, an attacker exploited a vulnerability in Gyazo's image upload server, gaining the ability to execute arbitrary commands on the underlying system. From there, the intruder moved into the database that stores user account records and image metadata. Helpfeel detected suspicious activity the same evening and severed the attacker's access by September 12, 2026. By that time, the database had already been read and copied.

The breach exposed approximately 23.62 million user records, which included names, email addresses, hashed passwords, user and device IDs, login session IDs, billing information, usage statistics, X integration tokens, and Google single sign‑on email addresses and profile data. In addition, around 490 million image metadata records were compromised, containing the image IDs that form Gyazo's shareable URLs, EXIF location data embedded in some images, and OCR‑extracted text pulled from screenshots. Helpfeel confirmed that no payment card numbers were part of the exposed data. The company noted that the bulk of the exposed image metadata dates to January 2019 or earlier.

Helpfeel closed the vulnerable upload server after detecting the intrusion and launched an internal investigation to determine the full scope of the breach. The company began notifying affected users directly about the incident. Helpfeel also reported the breach to Japan's Personal Information Protection Commission, the country's primary data protection regulator. Media coverage of the breach appeared on September 17 and 18, 2026, following the public disclosure on September 16.

Helpfeel described its investigation as ongoing as of mid‑September 2026, indicating that the final scope could shift as forensic work continues. The company stated that a list of private images had been compromised, though it did not disclose the volume of those images. No further details on specific remediation actions such as password resets or token revocation have been made public. The narrative ends here.

Sources

Sources available to members: 2 sources.

CSIDB