Skip to content
See the World Through ScienceA project of ALLATRA

Screenshot Service Gyazo Says 23.6 Million User Records Were Taken

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The Gyazo app mark, a white letter G formed by folded blue shapes on a rounded square tile.
The app mark of Gyazo, the screenshot sharing service operated by Helpfeel Inc. of Kyoto."Gyazo 2016" by 292Jacob, via wikimedia, CC-BY-SA-4.0 · CC-BY-SA-4.0

Helpfeel Inc., the Kyoto company behind the screenshot-sharing service Gyazo, said on Sept. 16, 2026, that an intruder had exploited a flaw in its image upload server and taken about 23.62 million user records, along with metadata for about 490 million uploaded images.

The records include email addresses and password hashes, and in its own notice, published in Japanese, Helpfeel asks Gyazo users to change their password, and to change it anywhere else they used the same one. The company also says the stolen image metadata contains the information image URLs are built from, so it could be used to reach and view the images themselves. Delivery of some images has been switched off while the investigation continues.

What each record holds varies by account, the company said, and can include a name or nickname, device and session IDs, and a linked X or Google sign-in token. No credit card or other payment data was taken. The 23.62 million include anonymous accounts with no email address registered, so Helpfeel says it is still working out how many people are affected.

The image metadata covers mainly images uploaded before January 2019, about 14.4% of all Gyazo image data by the company's count, with about 2.4 million further records taken separately. It can include image IDs, the address an image was uploaded from, any location data in the image, text read out of the image automatically, and hashed passphrases for private images. A list of private image files was also taken, Helpfeel said, and it cannot completely rule out that some private images were viewed.

The company says it detected the activity on the night of Sept. 11, cut off the route in and finished fixing the flaw by Sept. 12, and confirmed on Sept. 14 that data had left its systems. It reported the breach to Japan's Personal Information Protection Commission the next day. An outside firm is now examining the scope, and the counts are those Helpfeel had confirmed as of Sept. 16. Its other products, Helpfeel and Cosense, run on separate systems and show no leak, the company said.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Screenshot Service Gyazo Says 23.6 Million User Records Were Taken

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.