Desk live·
ForensicPost
Breaches/Exploitation/File 26-0918

Gyazo Server Flaw Exploited to Take 23.6 Million User Records and 490 Million Image Rows

The Japanese screenshot service’s operator said an attacker ran commands on a server on 11 September and dumped the database: password hashes, session identifiers, integration tokens, and the metadata that turns a private image ID into a working link, with the uploader’s IP and any location in the file.

Constructed geometry · not a chart of case data
JurisdictionJapanKyotothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGyazo users
ActorUnattributed
D. Kennedy9 min readConfidence: high3 sources reviewed

Helpfeel, the Kyoto company that operates the Gyazo screenshot service, disclosed on 18 September 2026 that an attacker had exploited a server vulnerability on 11 September to execute arbitrary commands and extract its database. The company detected the activity on 11 and 12 September. The dump held 23.62 million user records, including email addresses, password hashes, session identifiers, tokens for the X integration and the email addresses used for Google sign-in, and about 490 million image-metadata records.

Helpfeel noted that record counts are not user counts, since one person can hold several rows. It did not publish a user figure.

The Image Metadata Is The Exposure

Gyazo images are private by obscurity: each has an identifier, and the identifier forms the link. The metadata table holds those identifiers, alongside the IP address of the uploader, EXIF data including location where a photo carried it, and text extracted from the image by optical character recognition. An attacker with the table can construct the link to any of 490 million images, read what the service’s own OCR found in them and place the uploader on a map where the file allowed it. The images themselves were not reported taken; with the identifiers, they did not need to be.

Sessions And Tokens

Password hashes are the field notification letters mention. Session identifiers and integration tokens are the ones that matter on the day, because a valid session is a login without a password and an X token acts on the user’s account elsewhere. Helpfeel invalidated sessions and advised token rotation. The corpus filed the same distinction at 25-1207: a credential that persists until somebody removes it is the credential the attacker uses first.

A File The Record Usually Misses

The disclosure reached the English-language record because the operator published counts, dates and field lists in detail and because the numbers were large. The corpus recorded at 25-0502 how rarely that happens for incidents outside the Anglophone disclosure economies, and at 26-0820b how a Japanese provider’s candour is the reason its file exists. This one is the same, seven days from exploitation to a full public accounting.

How we reported this

Compiled from Helpfeel’s disclosure as reported and contemporaneous coverage, listed below. Counts are the company’s and are records, not users, as it stated. The vulnerability was not identified by CVE in the material reviewed. No attribution exists. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Gyazo server flaw exploited to steal 23.6 million user recordsBleepingComputer
  2. 23 Million User Records Compromised in Gyazo Data BreachSecurityWeek
  3. Helpfeel discloses Gyazo data breachHelp Net Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary