Notice Regarding Unauthorized Access to Gyazo(September 16, 2026)

We have confirmed unauthorized access by a third party to Gyazo, resulting in the external exposure of some user information and metadata related to uploaded images. We sincerely apologize for the concern and inconvenience this may cause Gyazo users.

We have blocked the paths used for the unauthorized access and fixed the vulnerability that caused the incident. We are continuing to investigate the scope of the impact and the possibility of secondary harm, including through an external specialist investigation.

For details, please read the full Gyazo notice.

What you should do now
Change your Gyazo password.
If you use the same or a similar password for any other service, change that password as well.

Be alert for suspicious emails or messages that exploit this incident. Before opening a link or attachment, check the sender and the content carefully.

Frequently Asked Questions

Why can’t I view an image or open a share link?

To help prevent secondary harm, we have temporarily disabled access to some images. Image delivery has resumed for images uploaded after the countermeasures against the unauthorized access were completed.

As of our current investigation, we have not confirmed the loss of image data as a result of the unauthorized access.


Can I check whether my information was affected?

We are investigating to identify the users whose information may have been exposed. We plan to contact potentially affected Gyazo users at their registered email addresses.

For anonymous accounts or other accounts for which contact by email is difficult, we plan to provide information through the Gyazo service interface. We are continuing to investigate the details of the information affected.

What information was exposed?

As of September 16, 2026, we have confirmed the external exposure of data relating to approximately 23.62 million Gyazo users, as well as some image metadata.

The user information may vary by user and can include a name, nickname, or other user-specified text; email address; password hash; user ID; device ID; login session ID; profile information; most recent login date and time; subscription plan; and billing status. For users who linked X, it may include an X integration token. For users who signed in with Google, it may include the Google SSO email address.

We have also confirmed the external exposure of metadata for approximately 490 million images, primarily images registered before January 2019, and an additional approximately 2.4 million image metadata records obtained under separately narrowed conditions. This metadata may include an image ID, source IP address, User-Agent, EXIF location information when present in an image, OCR text, image title, source URL, and a hash of the passphrase for private images.

Were payment card details exposed?

We have confirmed that payment information, such as credit card numbers, was not exposed.

Was my password exposed?

We have confirmed the exposure of password hashes, not passwords in plaintext. However, as a precaution, please change your Gyazo password. If you use the same or a similar password for another service, please change it there as well.

After reviewing the design and potential for misuse of exposed authentication-related information, we have already taken necessary measures, including invalidation or restrictions where appropriate.

Were image files themselves exposed?

At this time, we have confirmed the exposure of metadata related to uploaded images. However, the exposed metadata includes information used to construct image URLs. This information could be used to access affected images without authorization.

We have also confirmed that a list of private image files was obtained. We cannot completely rule out the possibility that some private images were viewed by a third party, and we are continuing a detailed investigation.

I use X integration or Sign in with Google. What should I do?

For users who linked X, the X integration token may be among the affected information. For users who signed in with Google, the Google SSO email address may be among the affected information. Please change your Gyazo password and check future individual notices and updates on this page.

Were Helpfeel or Cosense affected?

Helpfeel and Cosense are operated on system configurations separate from Gyazo. As of September 16, 2026, our investigation has not confirmed information exposure from the Helpfeel or Cosense systems as a result of this unauthorized access.

However, some images displayed through Gyazo on Helpfeel or Cosense may be unavailable because of the temporary suspension of Gyazo image delivery.

I received a suspicious email or message.

There may be suspicious emails or messages impersonating our company or Gyazo in connection with this incident. Please be cautious of messages that ask you to enter a password, verify your identity, download a file, or take action through a link when you did not request it.

We plan to provide our notices by email to the address registered with Gyazo or through the Gyazo service interface. If a message appears suspicious, do not use links in the message. Instead, contact us using the channels below.


Future updates
If our investigation identifies new facts, we will promptly publish them on the official Gyazo and Helpfeel websites. We will contact potentially affected users in stages as the investigation progresses.

Contact us
For inquiries about this incident, please use the following contact forms.