Gyazo data breach exposes 23.6 million user records

Gyazo data breach exposes 23.6 million user records

Attackers used a server flaw to steal 23.62 million Gyazo user records and 490 million image metadata entries; the platform is offline for maintenance.

The Gyazo data breach has been confirmed by Helpfeel, the company behind the screenshot and image sharing platform, after attackers exploited a server vulnerability to reach its database and take about 23.62 million user records. BleepingComputer reported the incident on September 18, 2026, and the company's own statements say the intrusion took place on September 11, 2026.

Gyazo is a cloud based screenshot and screen recording tool. It uploads a user's screen captures to the cloud automatically and creates a shareable link that can be posted in chats, forums or social media. The service is particularly popular in gaming communities and says it has 23 million users worldwide, who have collectively submitted 3.1 billion media items.

According to the company, suspicious activity was detected on September 12, and a vulnerability the attackers had used was fixed at that point, but by then the data had already been taken. Gyazo has since taken the platform offline for maintenance, describing the shutdown as a preventive measure. In a post on X, the company wrote: "Currently, the Gyazo service is temporarily suspended for maintenance as a preventive measure. We sincerely apologize for any inconvenience caused. Please wait a little longer until recovery."

Gyazo said its investigation confirmed that a third party had accessed its database and that user information and metadata tied to uploaded images had been disclosed without authorization. The exposed data differs from one user to another and may include one or more of the following: names or nicknames, email addresses, password hashes, user and device identifiers, login session identifiers, X integration tokens, Google single sign-on (SSO) email addresses, profile details, subscription information, billing status and usage statistics. A password hash is a scrambled form of a password that cannot be read directly, but it can still be attacked by a computer until the original password is guessed. A token, such as the X integration token, is a digital key that can allow access to a linked account, while a session identifier can let someone resume a session that is already logged in. Anonymous account records are also part of the exposed dataset, but Gyazo did not say what proportion of the records they represent.

The incident also exposed 490 million image metadata records, most of them associated with images uploaded to the service before January 2019. Metadata is information about a file rather than the file's visible content. In this case it includes the image identifiers used to build an image's URL, the IP address from which an image was uploaded, User-Agent strings (the text that identifies the browser or application making a request), EXIF location data (the geographic coordinates and camera details stored inside a photo), text pulled out of images by optical character recognition (OCR, software that reads the text inside a picture), image titles, source URLs and hashed passphrases for private images.

Helpfeel noted that image identifiers can potentially be used to reach the corresponding content, which is why it has temporarily disabled access to the files whose records were exposed. The attackers also obtained a list identifying private images, and the company said it cannot rule out that some of those images were viewed. Its investigation has found no signs that data was deleted because of the incident, and it has found no evidence that data was stolen from its other Helpfeel and Cosense services.

The company says it is notifying affected users directly, is carrying out the investigation with external experts and has contacted the authorities. Its advice to every Gyazo user is to change their password on the service, to change it on any other platform where the same credentials were used, and to remain alert for suspicious communications.

For readers who run websites or manage accounts for a business, the pattern here is worth taking seriously. A single vulnerable server can expose credentials, tokens and metadata for millions of people at once, and the fallout continues long after the flaw itself is patched. Reused passwords are the main amplifier of that damage, because a stolen password hash gives an attacker a target to crack that then works elsewhere. Session identifiers and app integrations should be reviewed and revoked wherever a provider allows it, and exposed billing or subscription details make fake invoices and convincing phishing messages more plausible. AEU-I, the AEU Group's security first IT, infrastructure and consulting service, exists for teams that want exactly this kind of review of their own accounts, credentials and permissions, and its service page sets out what that covers.

How to Protect Yourself

  1. Change your Gyazo password now, and if you used that same password on any other site, change it there as well.
  2. Turn on two-step login (a second code sent to your phone) for your email, social media and hosting accounts, because stolen email addresses and passwords make those accounts the next targets.
  3. Do not click login links in unexpected emails: open the website yourself by typing its address, since stolen contact details are often used to send fake login pages.
  4. Check which apps and services are connected to your accounts and remove any you no longer use, especially social media integrations.
  5. Look over your bank and subscription statements for charges you do not recognise, as billing and subscription details were among the exposed data.
  6. If you uploaded private screenshots or photos to a cloud service, review what is still online and delete anything sensitive you would not want shared.

Terms Explained

  • password hash A password that a computer has scrambled so it cannot be read directly, but which can still be cracked by someone who steals it.
  • metadata Information about a file, such as when it was made or where it came from, rather than the file's visible content.
  • EXIF location data Hidden details stored inside a photo, including the GPS coordinates of where it was taken and the camera used.
  • OCR Optical character recognition, software that turns the text inside a picture into text a computer can read and search.
  • SSO Single sign-on, a way of logging in to one service with an account you already have elsewhere, such as your Google account.
  • User-Agent string A short line of text your browser or app sends to a website to say what kind of device and software it is.
  • IP address The number that identifies the internet connection a device is using.

Related AEU services

  • AEU-I IT and security consulting