
Thank you for using the services provided by Helpfeel Inc.
Helpfeel Inc. (Head Office: Kyoto, Japan; Representative Director and CEO: Isshu Rakusai; hereinafter “Helpfeel”) has confirmed that Gyazo, our image-sharing service, was subject to unauthorized access by a third party resulting in a data breach, as announced in our previous notice on September 16, 2026 (hereinafter the “First Notice”).
Following further investigation since the First Notice, we have identified new information and clarified the scope of the impact, including the breakdown of user information involved. This notice outlines the facts we have confirmed as of September 25, 2026.
We sincerely apologize to all Gyazo users and other affected parties for the significant concern and prolonged inconvenience caused by this incident.
Please note that in this notice, the term “images” refers to all content captured and stored via Gyazo, including screenshots, GIFs, and videos. Furthermore, the contents of the “metadata” remain as described in the First Notice. Unless otherwise stated, all dates and times are in Japan Standard Time (JST).
Through our ongoing investigation following the First Notice, we newly confirmed that approximately 174 million metadata records associated with images previously deleted by users were also disclosed without authorization. We have confirmed that the affected metadata relates primarily to images deleted in or before February 2023 (*). The corresponding image files are currently inaccessible. The newly confirmed data breach does not include the deleted image files themselves.
We will notify affected individual users and companies by email on a rolling basis as soon as our investigation is complete.
Please note that the affected deletion processes are as follows:
Images deleted in or before February 2023
Accounts deleted in or before February 2023
*(This timeframe is based on when the image or account was deleted on Gyazo, not when the image was uploaded.)
As we continued to closely examine the data involved in the breach announced in the First Notice, we clarified the breakdown of user information and the proportion of the overall image metadata affected.
The facts confirmed as of this date are as follows:
Following a detailed review of the approximately 23.62 million user records announced in the First Notice, we have confirmed the following breakdown:
Anonymous users with no registered email address: Approximately 18.01 million records (Approx. 76%)
Users with a registered email address: Approximately 5.62 million records (Approx. 24%)
*(Due to rounding, the sum of the breakdown may not perfectly match the total.)
Gyazo can be used without registering an email address. Therefore, the approximately 23.62 million records announced in the First Notice include data related to anonymous accounts with no registered email address. The types and extent of data disclosed vary by user, and email addresses or similar information were not disclosed for all 23.62 million records.
As stated in the First Notice, we have confirmed that no payment information, including credit card numbers, was disclosed without authorization.
Regarding the X (formerly Twitter) Integration Token
Regarding the X (formerly Twitter) integration tokens that were reported as disclosed in the First Notice, subsequent investigation has confirmed that these tokens alone cannot be used to log in to or operate X accounts. Furthermore, as a precautionary measure to prevent further harm, we have already invalidated the authentication information related to OAuth integrations, including the tokens in question.
Following our detailed review since the First Notice, we have confirmed the following regarding the scope of the disclosed image metadata:
Affected Data | Record Count | Scope | Scale Relative to Total Images |
Image metadata | Approx. 490 million | Associated primarily with images uploaded in or before Jan 2019 | Approx. 14.4% |
Metadata retrieved using specific filtering criteria | 2.4 million | Under investigation | Approx. 0.07% |
Metadata for deleted images | Approx. 174 million | Associated primarily with images deleted in or before Feb 2023 | Approx. 5.1% |
We have not confirmed any unauthorized disclosure of image metadata other than what is listed above at this time.
Please note that all of the above figures refer to the number of image metadata records, not the number of image files themselves disclosed to a third party.
Based on our investigation to date, we have not confirmed any misuse of personal information or other secondary damage resulting from this incident.
Additionally, Helpfeel and Cosense, which are also provided by Helpfeel Inc., operate on system architectures that differ from Gyazo’s and are not connected to the access routes exploited in this unauthorized access.
Furthermore, our investigation to date has not confirmed any unauthorized disclosure of information from the Helpfeel or Cosense systems, nor have we found any evidence of unauthorized access or attacks against these services.
We will continue to investigate and monitor for any misuse of the disclosed information or secondary damage, in addition to the investigation being conducted by external specialists.
To prevent further harm, we are currently suspending Gyazo services, restricting certain functions, and temporarily disabling the viewing of saved images. However, based on our investigation to date, we have not confirmed any loss of image data uploaded by users to Gyazo as a result of the unauthorized access.
We sincerely apologize again for the significant concern and prolonged inconvenience this has caused.
Regarding the resumption of the service, we plan to restore access in phases after implementing additional security verification and necessary countermeasures.
We have already blocked the access routes used in the incident and completed the remediation of the vulnerability that was exploited. In addition, we are proceeding with the additional measures necessary for resumption, such as security verification across the entire service and countermeasures for the compromised authentication information.
When the service resumes, we are considering implementing a system where saved images will initially only be viewable by the owner. Users will then be able to revert them to their previous public state through their own actions.
We will provide a further update regarding our ongoing response, including the status of service resumption, around September 29, 2026.
Promptly after discovering this incident, we established an incident response task force to prevent further harm and investigate the root cause.
To accurately assess the scope and cause of the incident, in addition to our internal investigation, we are making inquiries to our cloud infrastructure providers, conducting a forensic investigation with external specialists, and reporting to and coordinating with relevant authorities in Japan and overseas. Our primary actions to date are as follows:
Reporting to the Personal Information Protection Commission (PIPC)
We submitted a preliminary report to the PIPC on September 15 in accordance with the Act on the Protection of Personal Information. We continue to report to and coordinate with them as our investigation progresses.
Reporting to the Ministry of Internal Affairs and Communications (MIC)
We have reported the occurrence of this incident and the status of our investigation to the MIC and continue to share necessary information and coordinate with them.
Reporting to Overseas Data Protection Authorities
We are also continuing to assess the impact on overseas users and are proceeding with reporting to and coordinating with relevant data protection authorities in accordance with laws and regulations in each country and region, including the GDPR.
Forensic Investigation by External Specialists
To accurately determine the scope of impact and the root cause of this incident, a forensic investigation is underway, conducted by external specialists. Based on the findings, we will implement necessary additional countermeasures and measures to prevent a recurrence.
Following the discovery of this incident, we implemented initial response measures to prevent the spread of damage and secondary harm. We are also strengthening security measures across the entire service and implementing measures to prevent a recurrence.
Blocking of Unauthorized Access Routes and Remediation of Vulnerabilities
We have blocked the access routes exploited in the unauthorized access and completed the remediation of the root cause vulnerability.
Invalidation and Restriction of Authentication Information
We carefully reviewed the technical specifications and potential for misuse of the disclosed authentication-related information. As a precautionary measure to prevent further harm, we invalidated and restricted the use of necessary authentication information.
Measures to Prevent Further Harm Regarding Image Viewing
To prevent the disclosed information from being misused to view images, we implemented measures to temporarily disable the viewing of certain images.
Additional Security Verification
We are conducting an additional security risk assessment across the entire service to identify potential vulnerabilities and security risks, and are proceeding with necessary additional countermeasures.
Establishing a Security Enhancement Structure with External Experts
We are establishing a structure to enhance security with the involvement of external experts and will reflect this in our future measures.
Enhancement of Security Training
We will strengthen security training for our developers to improve security throughout our development and operational processes.
We will continue working with external specialists to investigate the scope of the impact and the cause of this incident, while implementing measures to prevent a recurrence and preparing to resume the service.
If we identify any newly confirmed facts that should be shared, or if there is progress regarding the resumption of the service, we will promptly publish an update.
We sincerely apologize once again to all Gyazo users and other stakeholders for the significant concern and inconvenience caused by this incident.
For inquiries regarding this incident, please contact us through the appropriate channels below.
Customers using Helpfeel who have questions or concerns regarding this incident, please contact your Helpfeel representative.
For inquiries regarding Cosense, please contact us via the following form:
https://scrapbox.io/contact
For inquiries regarding Gyazo, please contact us via the appropriate form below:
Japanese: https://help-ja.gyazo.com/contact-us
English: https://help.gyazo.com/contact-us