Secretus logo
newsgyazohelpfeeldata-breach

The Gyazo Breach: An Unguessable Link Is Only Private Until the List Leaks

Helpfeel says a Gyazo intrusion exposed 23.62 million user records and 490 million image metadata records, including the IDs that build image URLs and OCR text.

·7 min read·Secretus Editorial

“Anyone with the link” is a security model with one assumption: that nobody ever gets the list of links. On September 16, Helpfeel published a notice about unauthorized access to Gyazo, its image-sharing service. Around 23.62 million user records were exposed—and around 490 million image metadata records, including the image IDs used to construct image URLs. Helpfeel says that metadata could be used by a third party to view the corresponding images without authorization.

Gyazo is a screenshot tool. That is the whole problem. Nobody screenshots their holiday photos into a paste-and-share utility; they screenshot the error message with the connection string in it, the terminal with the API key, the settings page mid-configuration, the chat they wanted a colleague to see.

What is confirmed

Helpfeel's notice states the intrusion occurred on September 11, 2026, when an attacker “exploited a vulnerability in Gyazo's image upload server to gain unauthorized access.” The company says it blocked the access routes and remediated the vulnerability by September 12, suspended image delivery as a precaution, and submitted a report to Japan's Personal Information Protection Commission.

The exposed user records—approximately 23.62 million—include names, email addresses, password hashes, user IDs, device IDs, login session IDs, social media tokens, profile information, subscription plans and billing status. Helpfeel states that no payment information, including credit card numbers, was disclosed.

The image metadata is the part that deserves a second read. Roughly 490 million records for images registered before January 2019, plus a further 2.4 million records, covering the image ID used to construct the image URL, source IP addresses, EXIF location data, OCR text and titles. Helpfeel says it obtained “a list identifying private images” and cannot rule out unauthorized viewing. It asks every user to change their password, and to change it anywhere they used the same or a similar one.

Three things in that list that are worse than they look

The image IDs are the access control. A Gyazo link is unlisted rather than access-controlled: possession of the URL is the permission. An identifier like that is not a secret in the cryptographic sense—it is a database column, and it leaks when the database does. Every image whose privacy rested on nobody guessing the ID is now resting on nobody using a list that was taken.

OCR text means the words may have travelled without the picture. Helpfeel lists OCR text among the exposed metadata categories. Optical character recognition of a screenshot produces the text that was on screen. We do not know what any particular record contains, and nobody has published a sample. But if you screenshotted a token, a password field in the clear, or a private message, the text of it is plausibly a metadata field rather than only pixels inside an image. Treat that as a reason to act, not as a confirmed disclosure of your specific content.

Social media tokens are live access, not a record of it. A leaked password hash needs cracking. A connected-account token may simply work. These should be revoked, not merely noted.

What remains unknown

The notice does not establish whether any images were actually viewed, which accounts were affected individually, who the attacker was, or whether the data has circulated since. Helpfeel says it cannot rule out unauthorized viewing—that is an honest statement of uncertainty, not a confirmation. There is also no public detail on the hashing algorithm used for the passwords, which is the single fact that would tell you how urgent the password reuse problem is. In the absence of that detail, assume the urgent case.

What to do, in order

  1. Change your Gyazo password, then change it everywhere you reused it. This is Helpfeel's own request and it is the highest-value step. Reuse is what turns one company's breach into your problem at ten other services.
  2. Revoke connected accounts. In the settings of whichever social or identity provider you linked—not in Gyazo—find the authorised-applications list and remove Gyazo, then re-link only if you still need it. Tokens are revoked at the issuer.
  3. Sign out all sessions if the service offers it, since login session IDs were in scope.
  4. Go and look at what you have uploaded. This is the step people skip because it is tedious and uncomfortable. Work backwards through your own history for screenshots containing credentials, tokens, internal URLs, customer data or anything covered by an NDA. Delete what should not be there.
  5. Rotate anything you find. Deleting the screenshot does not invalidate the key that was in it. If a token or password appeared in an image you uploaded, replace it at the system that issues it and revoke the old value explicitly.
  6. If this was work data, tell someone. A screenshot of production data in a personal image-sharing account is a reportable event at most organisations, and the disclosure window starts when you know, not when it is convenient.

The habit underneath

Screenshot sharing is popular because it is frictionless: one keystroke, and a link is on your clipboard. The friction it removes includes the moment where you would have thought about what is in the frame. Worth building back in, cheaply:

  • Crop before you share, not after. Most leaks in a screenshot are at the edges—a browser tab, a notification, a terminal line above the one you meant.
  • Never screenshot a secret to move it. An image is the worst container for a credential: it cannot be searched by your own tooling, it is invisible to secret scanners, and it persists in cloud photo libraries and clipboard managers long after the value is rotated.
  • Prefer a channel with an expiry to one with a permalink. The value of an unlisted URL is convenience; its cost is that it lasts forever and cannot be recalled once it is in someone's history.
  • Assume anything registered years ago still exists. Most of the metadata here is from images registered before January 2019. Old accounts do not forget on your behalf.

Where Secretus fits—and where it does not

There is a real technical distinction in this story, and it is worth stating precisely rather than as marketing. A Gyazo image ID is an identifier the service stores in order to serve the image; it is part of the database, so it is exposed when the database is. In Secretus's Standard mode, the decryption key stays in the URL fragment, which is the part of a link browsers do not send to the server, and the server stores ciphertext. Those are genuinely different properties.

The caveat matters just as much. A fragment key still lives wherever the link lives—the chat message, the mailbox, the clipboard history—so a link-based secret is only as private as the channel that carried it, and anyone who has the whole link can open it once. Secretus is a way to hand over a small value that expires, not a place to store screenshots and not an archive. If you are reaching for a screenshot tool to move a credential, the fix is to stop moving credentials as pictures at all.

Sources