DPO Insights

23.6 million records, 490 million images, and a notification problem

Published
Read time3 min read
DPO Insights

Helpfeel has disclosed a breach of its Gyazo image-sharing service in which an attacker exploited a vulnerability in an upload server to run arbitrary commands and reach backend systems. Roughly 23.62 million user records were taken, along with metadata covering around 490 million images. The containment was quick and competent. What makes the case instructive for any data protection officer is what came afterwards.

What happened, and how quickly

According to BleepingComputer, Help Net Security and SecurityWeek, the unauthorised access occurred on 11 September 2026 and suspicious activity was detected the same evening. By the early hours of 12 September, Helpfeel had blocked the identified access routes, terminated the attacker's connections and remediated the exploited vulnerability. The company reported the incident to Japan's Personal Information Protection Commission on 15 September.

The exposed user information includes names, email addresses, password hashes, user and device identifiers, X integration tokens, profile details, usage statistics and billing information. Payment card details were not compromised, according to the vendor. Users are being asked to change their passwords.

Key points
Detection to containment
Hours, not weeks — access blocked by early on 12 September.
Regulator notified
Japan's Personal Information Protection Commission, on 15 September 2026.
The awkward part
Metadata for ~490 million images, including information that could help reconstruct image URLs.

Metadata is not a lesser category

The headline number is the 23.6 million user records. The more interesting exposure is the image metadata. Reporting indicates it included information that could potentially be used to reconstruct image URLs and reach the uploaded content itself.

That is worth sitting with. A screenshot tool is used, constantly, for things people never consider sensitive at the moment of capture: a bug report containing a customer record, a slide from an internal deck, a chat window, an invoice. The images were not in the breach. The ability to find them may have been. Any assessment that treats "we only lost metadata" as a mild outcome has skipped the step where you ask what the metadata unlocks.

The notification problem nobody plans for

Helpfeel says it will notify affected users by email, and through the Gyazo web interface for anonymous accounts that have no registered email address. That second category is the one worth noting, because a lot of consumer and freemium services have it and very few have thought it through.

If a service deliberately lets people use it without an account, it has, by design, no way to contact them individually about a breach. The GDPR anticipates this: where individual notification would involve disproportionate effort, Article 34(3)(c) allows a public communication instead. But "we cannot reach them" is a conclusion you must be able to justify, not a convenience. The design decision to collect less is admirable; the consequence is that your incident plan needs a public notification route that has been written before you need it.

What to take from this

  • Include metadata in your data map. If your records of processing list "images" but not the identifiers, URLs, timestamps and device data around them, the map understates your exposure.
  • Know which clock you are on. Helpfeel notified Japan's PPC within four days. Under the UK GDPR and the GDPR the controller clock is 72 hours from awareness. If you operate across regions, the answer to "who do we tell, and by when?" should be written down before an incident, not researched during one.
  • Plan for users you cannot email. Anonymous or pseudonymous users still have rights. Decide now what your public notice looks like and where it goes.
  • Upload endpoints deserve attention. Anything that accepts a file from the internet and processes it is a high-value target. Treat those services as part of your critical attack surface.

The encouraging part of this incident is that detection and containment took hours. That is not luck; it is monitoring that worked. The organisations that struggle in the days after a breach are usually the ones that lost time at the start.

Get a named DPO who has run notification decisions before, not during, an incident.

Talk to a DPO

Common questions

Approximately 23.62 million user records, including names, email addresses, password hashes, user and device identifiers, X integration tokens, profile details, usage statistics and billing information, plus metadata covering roughly 490 million images. The vendor says payment card details were not compromised.

It can be. Identifiers, timestamps, device information and anything that allows an image to be located and linked to a user fall within the definition where they relate to an identifiable person. In this incident the metadata reportedly included information that could help reconstruct image URLs, which makes it consequential rather than incidental.

Under Article 34(3)(c) of the GDPR, where individual notification would involve disproportionate effort a controller may instead make a public communication or similarly effective measure. That route needs to be justified and prepared in advance, not improvised during the incident.

Sources

  1. Gyazo server flaw exploited to steal 23.6 million user records — BleepingComputer, 21 September 2026
  2. Hackers exploit Gyazo server flaw to steal 23.6 million user records — Help Net Security, 21 September 2026
  3. 23 Million User Records Compromised in Gyazo Data Breach — SecurityWeek, 21 September 2026