SHINDO6
Gyazo
Helpfeel Inc.
gyazo.com
User-related data~23.6Mrecords
LEAK CONFIRMEDOAuth / integration token / Session ID / tokenUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Sep 16, 2026
- Detected
- Sep 11, 2026
- Detection to disclosure
- 5 days
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Measures, no amount
- Compensation
- Not announced
- Corporate number
- 4130001068185
What leaked
IdentityName, Nickname
ContactEmail address, Google SSO email address
CredentialsPassword hash, Login session ID, X (Twitter) integration token, Hashes of private-image passphrases
Account dataUser ID, Profile information, Last login date/time, Subscription plan and billing status
Device & networkDevice ID, Uploader IP address, User-Agent, EXIF location data
Communications & contentImage ID, title, source URL, OCR text
How many
- User-related data ~23.6M records
- Anonymous users ~18M records
- Users registered with email ~5.6M records
Who is affected
- Members
- Anonymous users
Cause
A vulnerability in the image upload server was exploited, allowing a third party to execute arbitrary commands
Timeline
- Intrusion began
- Detected
- Intrusion stopped
- Detected
- Service suspended
- Reported to authority
- Service restored
- First disclosure
- Company issued an update
- Company issued an update
- Service suspended
- Company issued an update
- Second report
- Service restored
- Update published
- Company issued an update
Response
- Blocked the entry point
- Patched
- Password reset
- Revoked credentials
- Forensic investigation
- Vulnerability testing
- Service stopped
Revoked authentication-related credentials and OAuth integrations; blocked the intrusion route and fixed the vulnerability; security review of the entire service; forensic investigation by an outside specialist firm; asked users to change their passwords
What you should do
- Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
- Revoke connected apps and sign out everywhere. Your logged-in session itself was stolen
- Don't open links in emails from this company. The apology email itself may be fake
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Gyazo Help Center (Helpfeel), first notice Official notice · Sep 16, 2026
- Gyazo Help Center (Helpfeel), second notice Official notice · Sep 25, 2026
- ITmedia NEWS News · Sep 16, 2026
- piyolog Researcher · Sep 17, 2026
- ScanNetSecurity News · Sep 28, 2026
- Security Measures Lab Researcher · Sep 27, 2026
- gBizINFO Registry