← All briefs
Brief·4 sources18 Sept 2026

Gyazo Server Vulnerability Exploited To Expose 23 Million User Records

data-breachvulnerability-disclosurecredential-theftinitial-access

Summary

Gyazo, the image-sharing platform operated by Kyoto-based Helpfeel, has confirmed a significant data breach following the exploitation of a vulnerability in its image upload server. Attackers accessed approximately 23.62 million user records, including email addresses and password hashes, alongside roughly 490 million image metadata records predominantly relating to images uploaded before January 2019.

The breach was disclosed publicly on 17 September 2026 via a company notice. The image metadata exposure is particularly consequential: the leaked records include the IDs that compose Gyazo image links, meaning attackers could reconstruct or enumerate direct URLs to user-uploaded images. Helpfeel has begun notifying affected users and is engaging with the incident formally.

The scale of the metadata exposure is the more significant long-term concern. While the user record count of 23.62 million is itself substantial, the 490 million image metadata records create a secondary risk surface: enumeration attacks against still-live image URLs, potential re-identification of pseudonymous users, and targeted phishing using exposed email addresses combined with knowledge of a victim's uploaded content.

Timeline

  1. 18 September 2026
    BleepingComputer and SecurityAffairs report exploitation details
    Security media outlets confirmed the breach involved active exploitation of a server-side vulnerability and reported that exposed data includes email addresses and password hashes. The image upload server was identified as the attack vector.
  2. 17 September 2026
    Helpfeel publishes breach notification for Gyazo
    Kyoto-based Helpfeel confirmed attackers exploited a vulnerability in Gyazo's image upload server, exposing 23.62 million user records and 490 million image metadata records. The company began notifying affected users.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.

Gyazo Server Vulnerability Exploited To Expose 23 Million User Records | Deltabridge