<NEW>Notice Regarding Unauthorized Access to Gyazo (September 25, 2026)

We’re providing an update on the unauthorized third-party access to Gyazo and the resulting information exposure as of September 25, 2026.

Our investigation confirmed that metadata for approximately 174 million previously deleted images was also exposed.
Gyazo is currently unavailable to help prevent secondary harm, but we have not confirmed any loss of stored image data.
We sincerely apologize for the continued inconvenience and concern.

For information confirmed as of September 16, 2026, see Notice Regarding Unauthorized Access to Gyazo(September 16, 2026).

Frequently Asked Questions

When will Gyazo be available again?
We plan to restore the service in stages after completing additional security reviews and implementing the necessary measures.
We have blocked the path used for the unauthorized access and fixed the vulnerability that caused the incident.
We are currently carrying out additional service-wide security reviews and taking measures related to the exposed authentication information.
When service restoration begins, we plan to first make stored images viewable only by their owners.
We are also considering a mechanism that would allow users to restore their images to their previous sharing settings themselves.
We plan to provide another update on the service restoration status and our ongoing response by September 29, 2026.

What user information was affected?
We reviewed the approximately 23.62 million user records described in our initial notice and confirmed the following breakdown:
Approximately 18.01 million anonymous users without a registered email address (about 76%).
Approximately 5.62 million users with a registered email address (about 24%).
Because the figures are rounded, the totals may not match exactly.
Gyazo can be used without registering an email address, so the approximately 23.62 million records include data associated with anonymous users.
The types and scope of exposed information vary by user, and this does not mean that email addresses or other information were exposed for all approximately 23.62 million records.
We have confirmed that credit card numbers and other payment information were not included.

Can the exposed X (formerly Twitter) integration token be used to access my X account?
After reviewing the exposed X integration tokens, we confirmed that the token alone cannot be used to sign in to or operate an X account.
As a preventive measure against secondary harm, we have already invalidated the affected OAuth authentication information, including these tokens.

How much image metadata was exposed?
As of September 25, 2026, we have confirmed the following:
Metadata for approximately 490 million images, mainly uploaded before January 2019 (about 14.4% of all images).
Metadata for 2.4 million images obtained using specific selection criteria (about 0.07% of all images). The affected range is still under investigation.
Metadata for approximately 174 million deleted images, mainly deleted before February 2023 (about 5.1% of all images).
At this time, we have not confirmed exposure of image metadata outside the categories listed above.
These figures represent image metadata records and do not represent the number of image files that were externally exposed.

Has any secondary harm been confirmed?
As of September 25, 2026, our investigation has not confirmed unauthorized use of personal information or other secondary harm resulting from this incident.
We are continuing to investigate and monitor for misuse of the exposed information and other secondary harm in cooperation with external specialists.
There may be suspicious emails or messages impersonating our company or Gyazo in connection with this incident.
Be cautious of unexpected messages asking you to enter a password, verify your identity, download a file, or take action through a link.

Were Helpfeel or Cosense affected?
Helpfeel and Cosense operate on system configurations separate from Gyazo and are not connected to the access path used in this incident.
As of September 25, 2026, our investigation has not confirmed information exposure from the Helpfeel or Cosense systems.
We also have not identified evidence of unauthorized access to or attacks against either service.

Have my stored images been lost?
As of our current investigation, we have not confirmed the loss of stored image data as a result of this unauthorized access.
To help prevent secondary harm, Gyazo is currently unavailable, and access to some features and previously uploaded images is restricted.

Future updates
We are continuing the forensic investigation with external specialists, additional service-wide security reviews, the development of a stronger security framework involving external experts, and enhanced security training for developers.
If we confirm additional facts that should be shared or make progress toward restoring the service, we will provide an update promptly.

Contact us
If you have questions about this incident, Contact us.