The Gyazo data breach exposed user-related records and a very large volume of image metadata, but the headline numbers need careful interpretation. Helpfeel says approximately 23.62 million user-related records were disclosed, along with about 490 million image-metadata records and another roughly 2.4 million image-metadata records obtained under separate filtering criteria. The company is still determining the final number of affected individuals.
What should Gyazo users do now?
Change your Gyazo password now. If you used the same or a similar password on another service, change it there too. Watch for suspicious emails or messages related to the incident. Helpfeel says password hashes were among the exposed fields, but it has not reported plaintext password exposure or payment-card exposure.

What exactly was exposed in the Gyazo data breach?
Helpfeel says the attacker exploited a vulnerability in Gyazo’s image-upload server on September 11, gained the ability to execute arbitrary commands and accessed Gyazo database information.
The confirmed disclosure includes approximately 23.62 million user-related records. Depending on the account, those records can include email addresses, password hashes, device IDs, login session IDs and, for some users, X integration tokens or other account-related identifiers.
Helpfeel also confirmed disclosure of approximately 490 million image-metadata records, mainly associated with images registered in or before January 2019. Another roughly 2.4 million image-metadata records were retrieved using separate filtering criteria.
Possible metadata fields include image IDs, upload IP addresses, User-Agent strings, EXIF information such as location, OCR-extracted text, titles, source URLs and hashed passphrases associated with private images.
Does 23.62 million mean 23.62 million people were affected?
No. The company describes the figure as user-related records, not a final count of unique individuals. Helpfeel says the dataset includes anonymous accounts and that it is still working to determine the actual number of individuals whose personal information was disclosed.
That distinction matters because one person can be represented by more than one record or an account state may not correspond cleanly to one identified individual.
Does 490 million mean 490 million Gyazo images were stolen?
No. The confirmed figure refers to image metadata records, not 490 million confirmed image-file downloads.
Metadata can still be sensitive. An image ID may help construct a direct image URL. EXIF data can contain location information. OCR fields can contain text extracted from screenshots, including information that may be confidential depending on what the image showed.
The safest interpretation is therefore neither “only harmless metadata” nor “490 million private images were stolen.” The confirmed state is that extensive metadata was disclosed and some of that metadata can create meaningful privacy risk.
Were private Gyazo images viewed?
Helpfeel confirmed that the attacker obtained a list identifying private images. The company says it cannot rule out the possibility that some private images were viewed.
That does not mean all private images were accessed, and the company has not provided a confirmed number of private images that were actually viewed.
This distinction should remain explicit until the forensic investigation establishes a stronger answer.
Were plaintext passwords leaked?
Helpfeel says password hashes were among the possible exposed fields. It has not said that plaintext passwords were disclosed.
A password hash is not the same thing as a readable password, but exposure still matters because weak or reused passwords can create account-takeover risk if attackers can crack or otherwise abuse the associated credential data.
Were credit-card numbers exposed?
Helpfeel says payment information, including credit-card numbers, was not exposed in this incident based on its current investigation.
What if you reused your Gyazo password elsewhere?
1. Change the Gyazo password
Helpfeel recommends that Gyazo users change their password following the breach.
2. Change reused or similar passwords
If the same or a similar password was used on another service, replace it there as well. Do not limit the response to Gyazo if credential reuse exists.
3. Review linked-account exposure
If you used integrations such as X or Google sign-in, pay attention to Gyazo’s account-specific notifications and later guidance because the affected fields can differ by account configuration.
4. Watch for breach-themed phishing
Be cautious with messages claiming to offer breach checks, password recovery or private-image information. Use Gyazo’s official interface and Helpfeel/Gyazo notices rather than untrusted links.
5. Review sensitive screenshot exposure
If you stored screenshots containing locations, credentials, internal URLs, confidential text or other sensitive content, remember that EXIF, OCR, image IDs and related metadata can reveal information even when direct image viewing has not been confirmed.
What if you linked Gyazo to X?
Helpfeel says affected user records can include an X integration token where applicable. That does not prove every linked account token was stolen or successfully abused, but users with integrations should follow later account-specific notifications and current Gyazo guidance.
What if you signed in with Google?
The exposed information can include the email address associated with Google sign-in. The current official guidance still centers on securing the Gyazo account and following individual notifications rather than assuming that a Google account itself was compromised.
Can you check whether your own Gyazo account was affected?
Helpfeel is still identifying affected users. It says contactable users will be notified by email and that service-interface notifications will be used where email notification is not possible, including some anonymous accounts.
Until that process is complete, the absence of a message should not be treated as definitive proof that an account was unaffected.
Why EXIF and OCR metadata can matter
Image metadata is not automatically harmless. EXIF can contain device or location information, and OCR can reproduce text visible inside screenshots.
For a screenshot of a dashboard, internal tool, booking, document, map, private conversation or development environment, OCR-derived text and associated URLs can reveal sensitive context even when the underlying image itself is not proven to have been viewed.
The practical risk therefore depends heavily on what individual users uploaded and which metadata fields existed for those images.
Has Gyazo fixed the vulnerability?
Helpfeel says it blocked identified unauthorized access routes and remediated the exploited vulnerability by September 12.
That addresses the known intrusion path, but it does not erase information that may already have been copied. Users still need to complete the recommended account-security steps while the company investigates the full impact.
Were Helpfeel or Cosense also breached?
Helpfeel says the separate Helpfeel and Cosense systems use different architecture and that its investigation has not confirmed information disclosure or attack traces in those systems.
That is a current negative finding, not a reason to merge unrelated services into the confirmed Gyazo breach scope.
What remains unknown?
- The final number of unique affected individuals.
- The exact exposed fields for every individual account.
- How many private images, if any, were actually viewed.
- Whether exposed session or integration credentials were successfully abused.
- The attacker’s identity and motive.
- The precise technical class of the exploited vulnerability.
- The final regulatory and forensic outcome.
Gyazo data breach: direct answers
Should every Gyazo user change their password?
Yes. Helpfeel’s current guidance is for Gyazo users to change their Gyazo password and also change reused or similar passwords on other services.
Were passwords stored in plaintext?
The company reports exposure of password hashes, not plaintext passwords.
Were payment cards exposed?
Helpfeel says payment information including credit-card numbers was not exposed.
Were 490 million images stolen?
No such claim is supported. The confirmed figure is approximately 490 million image-metadata records.
Were private images accessed?
Helpfeel says it cannot rule out that some private images were viewed, but it has not confirmed mass private-image access or provided a final count.
What happens next?
Helpfeel says the investigation and affected-user identification process are continuing. New findings about private-image access, affected-user counts, notifications, authentication data or regulator action should update this same canonical page.
Verification method
ThePulseSignal reviewed Helpfeel’s primary breach notice, the official Gyazo incident FAQ, Helpfeel’s later scope update and current secondary reporting. The review separated record counts from unique people, metadata exposure from confirmed image-file access, and confirmed private-image risk from unresolved viewing scope.
Limitations
The final unique-person count, account-by-account exposed fields, extent of private-image viewing, attacker attribution and final forensic or regulatory findings remain unresolved. These points should be updated when Helpfeel publishes stronger evidence.