Skip to content

Gyazo

Disclosed Sep 16, 20269 days ago23,620,000 affectedConfirmed

Official notice

Gyazo server flaw exploited to steal 23.62 million user records

Screenshot service Gyazo, run by Helpfeel, said an attacker exploited a server vulnerability and stole 23.62 million user records, including emails, password hashes, session IDs and X tokens, plus 490 million image metadata records. The service was suspended for maintenance.

What is known

People affected23,620,000 (as reported by the organization)
DisclosedSep 16, 2026
DiscoveredSep 12, 2026
AttackHacking
Data exposedNames, Emails, Passwords, Credentials and tokens, IP addresses, Location, Other
SectorTech · JP
StatusConfirmed

Sources

Source
Helpfeel news releasecorp.helpfeel.com · Official notice
Gyazo server flaw exploited to steal 23.6 million user recordsbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalSep 1623,620,000
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Gyazo

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.