Gyazo Product Updates logo

Product Updates

Back to Homepage
English
  • 日本語
Subscribe to Updates

Labels

  • All Posts
  • Performance Boost
  • New Feature
  • UI Update
  • Security Update
  • Mac
  • Windows
  • iOS
  • Android
  • Browser Extension
  • How-to
  • Announcement
  • Web

Jump to Month

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
Powered by

Create yours, for free!

Announcement
today

Notice Regarding the Resumption of Gyazo Services

Thank you for using the services provided by Helpfeel Inc.

Helpfeel Inc. (Head Office: Kyoto, Japan; Representative Director and CEO: Isshu Rakusai; hereinafter “Helpfeel”) temporarily suspended Gyazo, our image-sharing service, as a precautionary measure to prevent further harm following unauthorized access by a third party and a resulting data breach. We resumed the service on September 26, 2026.

We sincerely apologize to all Gyazo users for the significant concern and prolonged inconvenience caused by the service suspension.

Please note that in this notice, the term “images” refers to all content captured and stored via Gyazo, including screenshots, GIFs, and videos. Unless otherwise stated, all dates and times are in Japan Standard Time (JST).

Service Resumption

Following the discovery of this incident, we blocked the  routes believed to have been used in the unauthorized access and addressed the vulnerability believed to have been the cause of the incident. We also conducted additional security verification across the entire service and implemented necessary countermeasures.

Based on these measures and verification efforts, we resumed Gyazo services on September 26, 2026.

Following the resumption of the service, we will continue our investigation and verification with the involvement of external specialists and implement additional measures as necessary.

Current Image Viewing Status

As part of the service resumption, all images uploaded before the unauthorized access occurred are currently set so that they can only be viewed by their owners. As a result, images that were previously viewable by others are also temporarily inaccessible to anyone other than the owner.

To avoid images becoming accessible to third parties in ways users do not intend, we have decided not to automatically restore all images to their previous status. Instead, users can review the content of their images and choose whether to resume image delivery.

We apologize for the inconvenience and appreciate your understanding.

Resuming Image Delivery

After the service resumes, please review the content of your images and choose either “Resume delivery”  for each image.

Images for which delivery is resumed will return to the visibility settings that were in place before this incident, such as “Only me” or “Anyone with the link.” Before resuming delivery, please carefully review both the content of the image and its visibility setting to help ensure that the image is not unintentionally shared with others.

We apologize for the inconvenience and ask that you review the relevant images before proceeding.

How to Resume Image Delivery

If you wish to resume image delivery, you can do so using one of the following methods:

  • Resuming images individually
    Open the relevant image page, review the content, and select “Resume delivery.”
  • Resuming multiple images
    Select the images you wish to resume from the image list, then select “Resume delivery” from the side menu.
  • Resuming all images at once
    From the “Images with suspended delivery” section of the Settings page, you can resume delivery for all images at once. This option may be useful if you have a large number of images and reviewing them individually would be difficult.
    Please note that when delivery is resumed in bulk, each image will return to the visibility setting that was in place before this incident. If there are images for which you would like to review the visibility setting again, we recommend checking those images individually before resuming delivery.

Even after image delivery has been resumed, you can change the visibility setting through the “Permission” feature and return the image to a state where it is viewable only by you.

Special Measures for Free Plan Users

Under normal circumstances, users on the Free plan cannot access their image history beyond a certain period. As a special measure, however, we are temporarily making all images uploaded before the unauthorized access occurred available for users to review.

This allows Free plan users to review their past images and choose whether to resume delivery or keep delivery suspended.

Request to Change Your Password

To help prevent further harm resulting from this incident, we ask all Gyazo users to change their passwords.

If you use the same or a similar password for Gyazo and any other services, we ask that you also change your passwords for those services.

Please also remain vigilant for any suspicious emails, messages, or other communications related to this incident.

Next Steps

Following the resumption of the service, we will continue our investigation with the involvement of external specialists and proceed with necessary security measures, including reviewing our authentication, authorization, and access controls and strengthening our monitoring and audit processes.

We sincerely apologize once again to all Gyazo users and other stakeholders for the significant concern and inconvenience caused by this incident.

Contact Information

Japanese: https://help-ja.gyazo.com/contact-us
English: https://help.gyazo.com/contact-us

Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo (Update 2)
Announcement
yesterday

Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo (Update 2)

Thank you for using the services provided by Helpfeel Inc.

Helpfeel Inc. (Head Office: Kyoto, Japan; Representative Director and CEO: Isshu Rakusai; hereinafter “Helpfeel”) has confirmed that Gyazo, our image-sharing service, was subject to unauthorized access by a third party resulting in a data breach, as announced in our previous notice on September 16, 2026 (hereinafter the “First Notice”).

Following further investigation since the First Notice, we have identified new information and clarified the scope of the impact, including the breakdown of user information involved. This notice outlines the facts we have confirmed as of September 25, 2026.

We sincerely apologize to all Gyazo users and other affected parties for the significant concern and prolonged inconvenience caused by this incident.

Please note that in this notice, the term “images” refers to all content captured and stored via Gyazo, including screenshots, GIFs, and videos. Furthermore, the contents of the “metadata” remain as described in the First Notice. Unless otherwise stated, all dates and times are in Japan Standard Time (JST).

1. Newly Confirmed Information

Through our ongoing investigation following the First Notice, we newly confirmed that approximately 174 million metadata records associated with images previously deleted by users were also disclosed without authorization. We have confirmed that the affected metadata relates primarily to images deleted in or before February 2023 (*). The corresponding image files are currently inaccessible. The newly confirmed data breach does not include the deleted image files themselves.
We will notify affected individual users and companies by email on a rolling basis as soon as our investigation is complete.

Please note that the affected deletion processes are as follows:

  • Images deleted in or before February 2023
  • Accounts deleted in or before February 2023

*(This timeframe is based on when the image or account was deleted on Gyazo, not when the image was uploaded.)

2. Scope and Impact of the Unauthorized Access Following Ongoing Investigation

As we continued to closely examine the data involved in the breach announced in the First Notice, we clarified the breakdown of user information and the proportion of the overall image metadata affected.

The facts confirmed as of this date are as follows:

(2-1) Impact and Scope of the Approximately 23.62 Million User Records

Following a detailed review of the approximately 23.62 million user records announced in the First Notice, we have confirmed the following breakdown:

Anonymous users with no registered email address: Approximately 18.01 million records (Approx. 76%)
Users with a registered email address: Approximately 5.62 million records (Approx. 24%)
*(Due to rounding, the sum of the breakdown may not perfectly match the total.)

Gyazo can be used without registering an email address. Therefore, the approximately 23.62 million records announced in the First Notice include data related to anonymous accounts with no registered email address. The types and extent of data disclosed vary by user, and email addresses or similar information were not disclosed for all 23.62 million records.

As stated in the First Notice, we have confirmed that no payment information, including credit card numbers, was disclosed without authorization.

Regarding the X (formerly Twitter) Integration Token

Regarding the X (formerly Twitter) integration tokens that were reported as disclosed in the First Notice, subsequent investigation has confirmed that these tokens alone cannot be used to log in to or operate X accounts. Furthermore, as a precautionary measure to prevent further harm, we have already invalidated the authentication information related to OAuth integrations, including the tokens in question.

(2-2) Scope and Impact of the Disclosed Image Metadata

Following our detailed review since the First Notice, we have confirmed the following regarding the scope of the disclosed image metadata:

Affected Data

Record Count

Scope

Scale Relative to Total Images

Image metadata

Approx. 490 million

Associated primarily with images uploaded in or before Jan 2019

Approx. 14.4%

Metadata retrieved using specific filtering criteria

2.4 million

Under investigation

Approx. 0.07%

Metadata for deleted images

Approx. 174 million

Associated primarily with images deleted in or before Feb 2023

Approx. 5.1%

We have not confirmed any unauthorized disclosure of image metadata other than what is listed above at this time.

Please note that all of the above figures refer to the number of image metadata records, not the number of image files themselves disclosed to a third party.

3. Secondary  Harm and Impact on Other Helpfeel Services

Based on our investigation to date, we have not confirmed any misuse of personal information or other secondary damage resulting from this incident.

Additionally, Helpfeel and Cosense, which are also provided by Helpfeel Inc., operate on system architectures that differ from Gyazo’s and are not connected to the access routes exploited in this unauthorized access.

Furthermore, our investigation to date has not confirmed any unauthorized disclosure of information from the Helpfeel or Cosense systems, nor have we found any evidence of unauthorized access or attacks against these services.

We will continue to investigate and monitor for any misuse of the disclosed information or secondary damage, in addition to the investigation being conducted by external specialists.

4. Image Preservation Status and Preparations for Service Resumption

To prevent further harm, we are currently suspending Gyazo services, restricting certain functions, and temporarily disabling the viewing of saved images. However, based on our investigation to date, we have not confirmed any loss of image data uploaded by users to Gyazo as a result of the unauthorized access.

We sincerely apologize again for the significant concern and prolonged inconvenience this has caused.

Regarding the resumption of the service, we plan to restore access in phases after implementing additional security verification and necessary countermeasures.

We have already blocked the access routes used in the incident and completed the remediation of the vulnerability that was exploited. In addition, we are proceeding with the additional measures necessary for resumption, such as security verification across the entire service and countermeasures for the compromised authentication information.

When the service resumes, we are considering implementing a system where saved images will initially only be viewable by the owner. Users will then be able to revert them to their previous public state through their own actions.

We will provide a further update regarding our ongoing response, including the status of service resumption, around September 29, 2026.

5. Investigation by External Specialists and Reporting to Authorities

Promptly after discovering this incident, we established an incident response task force to prevent further harm and investigate the root cause.

To accurately assess the scope and cause of the incident, in addition to our internal investigation, we are making inquiries to our cloud infrastructure providers, conducting a forensic investigation with external specialists, and reporting to and coordinating with relevant authorities in Japan and overseas. Our primary actions to date are as follows:

  • Reporting to the Personal Information Protection Commission (PIPC)
    We submitted a preliminary report to the PIPC on September 15 in accordance with the Act on the Protection of Personal Information. We continue to report to and coordinate with them as our investigation progresses.
  • Reporting to the Ministry of Internal Affairs and Communications (MIC)
    We have reported the occurrence of this incident and the status of our investigation to the MIC and continue to share necessary information and coordinate with them.
  • Reporting to Overseas Data Protection Authorities
    We are also continuing to assess the impact on overseas users and are proceeding with reporting to and coordinating with relevant data protection authorities in accordance with laws and regulations in each country and region, including the GDPR.
  • Forensic Investigation by External Specialists
    To accurately determine the scope of impact and the root cause of this incident, a forensic investigation is underway, conducted by external specialists. Based on the findings, we will implement necessary additional countermeasures and measures to prevent a recurrence.

6. Security Measures and Prevention of Recurrence

Following the discovery of this incident, we implemented initial response measures to prevent the spread of damage and secondary harm. We are also strengthening security measures across the entire service and implementing measures to prevent a recurrence.

(6-1) Completed Measures

  • Blocking of Unauthorized Access Routes and Remediation of Vulnerabilities
    We have blocked the access routes exploited in the unauthorized access and completed the remediation of the root cause vulnerability.
  • Invalidation and Restriction of Authentication Information
    We carefully reviewed the technical specifications and potential for misuse of the disclosed authentication-related information. As a precautionary measure to prevent further harm, we invalidated and restricted the use of necessary authentication information.
  • Measures to Prevent Further Harm Regarding Image Viewing
    To prevent the disclosed information from being misused to view images, we implemented measures to temporarily disable the viewing of certain images.

(6-2) Ongoing and Future Measures

  • Additional Security Verification
    We are conducting an additional security risk assessment across the entire service to identify potential vulnerabilities and security risks, and are proceeding with necessary additional countermeasures.
  • Establishing a Security Enhancement Structure with External Experts
    We are establishing a structure to enhance security with the involvement of external experts and will reflect this in our future measures.
  • Enhancement of Security Training
    We will strengthen security training for our developers to improve security throughout our development and operational processes.

We will continue working with external specialists to investigate the scope of the impact and the cause of this incident, while implementing measures to prevent a recurrence and preparing to resume the service.

If we identify any newly confirmed facts that should be shared, or if there is progress regarding the resumption of the service, we will promptly publish an update.

We sincerely apologize once again to all Gyazo users and other stakeholders for the significant concern and inconvenience caused by this incident.

Contact Information

For inquiries regarding this incident, please contact us through the appropriate channels below.

  • Customers using Helpfeel who have questions or concerns regarding this incident, please contact your Helpfeel representative.
  • For inquiries regarding Cosense, please contact us via the following form:
    https://scrapbox.io/contact
  • For inquiries regarding Gyazo, please contact us via the appropriate form below:
    Japanese: https://help-ja.gyazo.com/contact-us
    English: https://help.gyazo.com/contact-us



Announcement
4 days ago

⚠️ Update on Gyazo Maintenance

Gyazo is currently undergoing maintenance to ensure that you can use the service more safely. Access to the service has been temporarily suspended during this process.

Images and other data previously saved to Gyazo remain intact. We are currently preparing a way for you to review your saved data and make it available for viewing and sharing again.

We apologize for the inconvenience and concern. Please bear with us while we prepare to restore the service.

Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo
a week ago

Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo

Helpfeel Inc. (Head Office: Kyoto, Japan; Representative Director and CEO: Isshu Rakusai; hereinafter “Helpfeel”) has confirmed that Gyazo, our image-sharing service, was subject to unauthorized access by a third party, resulting in the unauthorized disclosure of user information and certain metadata associated with uploaded images.

We have blocked all access routes used in the incident and have completed remediation of the vulnerability that was exploited. We continue to prioritize measures to prevent further harm while investigating the scope and impact of the incident.

We sincerely apologize to all Gyazo users and other affected parties for the significant concern and inconvenience caused by this incident.

Our investigation remains ongoing, and additional information may come to light. The following summarizes the information we have confirmed as of September 16, 2026. 

In this notice, the term “images” refers to all content captured and stored via Gyazo, including screenshots, GIFs, and videos.  Unless otherwise stated, all dates and times are in Japan Standard Time (JST).

[Updated September 24, 2026, at 18:20] We are currently performing maintenance to ensure the security of Gyazo, and the service is temporarily suspended. Regarding the password reset mentioned below under '3. Response to Gyazo Users' please complete this after the service has resumed. 

1. Incident Overview

On September 11, 2026, a third party exploited a vulnerability in Gyazo’s image upload server to gain unauthorized access to our systems and execute arbitrary commands.

That evening, we detected suspicious activity and began investigating and responding to the incident. By the early hours of September 12, we had blocked the identified access routes and terminated unauthorized connections established by the third party.

Our subsequent investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata associated with uploaded images had been disclosed without authorization.

2. Scope and Impact of the Unauthorized Access

Our investigation remains ongoing, and additional information may come to light. The facts confirmed as of September 16, 2026, are as follows.

(1) User Information: Approximately 23.62 Million Records

We have confirmed that approximately 23.62 million records containing data related to Gyazo users were disclosed without authorization.

The data includes:

  • Name (any text entered by the user, such as a name or nickname)
  • Email address
  • Password hash
  • User ID
  • Device ID
  • Login session ID
  • X (formerly Twitter) integration token (if connected)
  • Email address associated with Google SSO (if connected)
  • Profile information
  • Language preference
  • Registration date and time
  • Last login date and time
  • Subscription plan
  • Billing status (does not include credit card numbers or other payment method information)
  • Usage statistics

The types and extent of data involved vary by user. We are continuing to investigate the details of the affected data and the potential for further harm. We have carefully reviewed the technical characteristics of the authentication-related information involved in the breach and its potential for misuse, and have already implemented the necessary measures, including invalidation and restrictions.

The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar information. We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization.

We have confirmed that no payment information, including credit card numbers, was disclosed without authorization.

(2) Image Metadata: Approximately 490 Million Records

We have confirmed that approximately 490 million metadata records associated primarily with images registered in or before January 2019 (approximately 14.4% of all image-related data) were disclosed without authorization. In addition, metadata relating to approximately 2.4 million images was separately retrieved using specific filtering criteria and was also disclosed without authorization.

The metadata involved in the breach includes:

  • Image ID (information used to construct the image URL)
  • Source IP address used for the upload
  • User-Agent
  • EXIF location data (if contained in the image)
  • OCR text extracted from the image
  • Image title
  • Source URL and other metadata
  • Hashed passphrase for private images
  • Other related information

The affected metadata includes information used to construct Gyazo image URLs. This information could be used by a third party to access and view the corresponding images without authorization. We have temporarily disabled viewing of some images to prevent further harm.

We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.

Our investigation to date has not confirmed any loss of image data resulting from the unauthorized access.

(3) Impact on Other Helpfeel Services

Helpfeel and Cosense, which are also provided by Helpfeel Inc., have system architectures that differ from Gyazo’s. Based on our investigation to date, we have not confirmed any unauthorized disclosure of information from the Helpfeel or Cosense systems as a result of this incident.

However, some images displayed within Helpfeel and Cosense using Gyazo may currently be unavailable due to the suspension of Gyazo image delivery in response to this incident.

3. Response to Gyazo Users

(1) Notification to Users

We plan to send notifications regarding this incident to the registered email addresses of Gyazo users who may have been affected. We are currently working to identify users whose information was disclosed without authorization and will determine which users to notify based on the progress of our investigation.

For users we are unable to reach by email, such as those with anonymous accounts without a registered email address or similar contact information, we plan to provide notifications through the Gyazo web interface.

We are continuing to investigate the details of the affected information. If we identify any additional information that should be shared, we will promptly publish an update.

(2) Actions We Ask Users to Take to Prevent Further Harm

To help prevent further harm resulting from this incident, we ask all Gyazo users to change their passwords.

If you use the same or a similar password for Gyazo and any other services, we ask that you also change your passwords for those services.

Please also remain vigilant for any suspicious emails, messages, or other communications related to this incident.

(3) Contact Information

For inquiries regarding this incident, please contact us through the appropriate form below.

Japanese:
https://help-ja.gyazo.com/contact-us

English:
https://help.gyazo.com/contact-us

4. Timeline and Response

September 11

Unauthorized access to Gyazo occurred. We began investigating and responding to the incident.

September 12

We completed our initial response measures and remediated the vulnerability that was exploited.

September 14

Our investigation confirmed that information from Gyazo had been disclosed without authorization. We implemented precautionary measures, including suspending image delivery, while continuing to investigate the scope of the impact, with the prevention of further harm as our highest priority.

September 15

We implemented additional measures to prevent further harm. We resumed delivery of images newly uploaded after we had completed measures to address the unauthorized access. We also submitted a report to Japan’s Personal Information Protection Commission.

September 16

We published this notice setting out the scope and impact of the data breach confirmed as of this date.

5. Next Steps

(1) We will continue to prioritize measures to prevent further harm while investigating the scope and impact of the data breach through a forensic investigation conducted by external specialists. If our ongoing investigation identifies any additional information that should be shared, we will promptly publish an update.

(2) We are continuing to assess applicable reporting requirements and to prepare and submit the necessary reports to, and consult with, relevant data protection and regulatory authorities in Japan and other applicable jurisdictions. We are also preparing notifications for Gyazo users. We will determine which users to contact based on the progress of our investigation and will notify them on a rolling basis.

(3) To fully investigate this incident and prevent a recurrence, we will strengthen our security measures, including reviewing our authentication, authorization, and access controls; enhancing our monitoring and audit processes; and improving our secure design, development, and review practices. We will also review our other services for similar vulnerabilities.

We take this incident very seriously and are fully committed to preventing a recurrence and restoring the trust of our users and other stakeholders.




Announcement
a week ago

⚠️ Image Viewing Partially Restored

Newly uploaded images are now available as usual. Some images remain unavailable due to emergency maintenance. We sincerely apologize for the inconvenience.

Announcement
a week ago

⚠️ Notice Regarding Temporary Image Viewing Restrictions

We have currently suspended the image delivery servers for some images due to emergency maintenance. Errors will appear for the affected images. We sincerely apologize for the inconvenience.

New FeatureMac
a week ago

Capture Fast or Frame It Carefully—Now for Screenshots and Video

Screenshot of Gyazo Studio Mode on Mac. A 1280 × 720 capture area is selected on screen, with resize handles around the frame and an aspect ratio menu showing Free, 1:1, 4:3, 3:2, 16:9, and 9:16 options. Capture controls are displayed below the selected area, showing that the frame can be adjusted before capturing.

Gyazo for Mac now supports Quick Mode and Studio Mode for both screenshots and video, so you can choose the right way to capture for the task at hand.

Quick Mode is there when speed matters. Select an area and capture immediately, making it ideal for quickly saving something you noticed, sharing an issue with a teammate, or recording a short interaction before it disappears.

Studio Mode is for captures you want to present clearly. Before taking a screenshot or starting a recording, you can adjust the position and size of the selected area. That means less unnecessary content around the edges, less cropping afterward, and a result that is easier for others to understand at a glance.

For screenshots, Studio Mode is also useful when creating a series of images. You can keep the capture area fixed while interacting with the app behind it and take multiple captures with consistent framing.

  • Capture immediately with Quick Mode when speed is the priority.
  • Refine the frame with Studio Mode when clarity and presentation matter.
  • Set separate defaults for screenshots and video to match your usual workflow.
  • Open the other mode from the three-dot menu whenever you need to switch temporarily.

This is especially helpful when creating product documentation, bug reports, tutorials, onboarding materials, presentations, and demos. Instead of fixing the framing after every capture, you can make the image or video easier to use from the moment you capture it.

Spend less time adjusting captures afterward—and more time putting them to work.

This improvement is available to all Gyazo for Mac users.

Download the latest version

New FeatureAnnouncement
3 weeks ago

Bring Your Gyazo Captures into Canva

Gyazo is now available as an app in Canva. Search for Gyazo from Canva Apps and add it to your workspace.

Sign in to Gyazo in the same browser and connect your account to access your Gyazo gallery directly from the Canva editor.

  • Find and add Gyazo from Canva Apps
  • Browse your existing Gyazo captures without leaving the Canva editor
  • Place captures directly into your designs without downloading and re-uploading files

This integration makes it easier to turn captures you have already saved in Gyazo into presentations, social content, documents, and other designs while staying in your Canva workflow.

Open Canva

Choose Your Maximum Video Recording Time on Mac
New FeatureMac
4 weeks ago

Choose Your Maximum Video Recording Time on Mac

Gyazo Pro users can now set the maximum video recording time directly from the Gyazo for Mac settings.

Choose the duration that best fits what you’re capturing:

  • 7 sec
  • 30 sec
  • 1 min
  • 3 min
  • 5 min
  • 10 min

Whether you’re making a quick visual note or recording a longer workflow, you can set an appropriate limit before you start recording.

This setting is available to Gyazo Pro users on Mac. Free users continue to record videos with the standard 7-second limit.

Download the Latest Version

A New Collections Page for Easier Organization
New FeatureWeb
a month ago

A New Collections Page for Easier Organization

We’ve improved Collections on Gyazo Web to make it easier to organize, find, and revisit your captures.

You can now:

  • Open all your Collections from the sidebar with the new dedicated Collections page.
  • Sort Collections by updated date or name, with your selected sort order remembered for your next visit.
  • Pin frequently used Collections to keep them accessible in the sidebar.
  • Continue where you left off when returning to the Collections page, with your previous scroll position restored.
  • Browse smoothly as more Collections load automatically while you scroll.
  • See up to four capture thumbnails for each Collection, making its contents easier to recognize at a glance.

The sidebar now focuses on pinned Collections, while the dedicated Collections page gives you a convenient place to browse the Collections you’ve organized.

These improvements make it simpler to return to past captures and put them to use again.

Open Collections