Gyazo, the image-sharing platform operated by Kyoto-based Helpfeel, has confirmed a significant data breach following the exploitation of a vulnerability in its image upload server. Attackers accessed approximately 23.62 million user records, including email addresses and password hashes, alongside roughly 490 million image metadata records predominantly relating to images uploaded before January 2019.
The breach was disclosed publicly on 17 September 2026 via a company notice. The image metadata exposure is particularly consequential: the leaked records include the IDs that compose Gyazo image links, meaning attackers could reconstruct or enumerate direct URLs to user-uploaded images. Helpfeel has begun notifying affected users and is engaging with the incident formally.
The scale of the metadata exposure is the more significant long-term concern. While the user record count of 23.62 million is itself substantial, the 490 million image metadata records create a secondary risk surface: enumeration attacks against still-live image URLs, potential re-identification of pseudonymous users, and targeted phishing using exposed email addresses combined with knowledge of a victim's uploaded content.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.