Gyazo Data Breach Exposes 23.6 Million User Records and 490 Million Image Metadata Records
Image-sharing platform Gyazo has confirmed a data breach in which attackers exploited a vulnerability in its servers and stole approximately 23.62 million user records.
Gyazo is a cloud-based screenshot and screen-recording service operated by Helpfeel. The platform automatically uploads screenshots and recordings to the cloud, creating shareable links for use in chats, forums, social media, and other services.
The service is particularly popular among gamers. According to Gyazo’s website, it has more than 23 million users worldwide who have uploaded approximately 3.1 billion media items.
When the Gyazo breach happened
According to the company, the incident occurred on September 11, 2026, when an attacker accessed Gyazo’s database and obtained approximately 23.62 million user records.
Gyazo detected suspicious activity on September 12 and fixed the vulnerability used in the attack. However, the data had already been stolen by that time.
The company has temporarily taken the platform offline while it performs maintenance.
“As a precautionary measure, the Gyazo service is currently temporarily suspended for maintenance. We apologize for any inconvenience this may cause. Please wait for a while until it is restored.”
What information was exposed?
Gyazo said the exposed information varies by user account and may include one or more of the following:
- Name or nickname
- Email address
- Password hash
- User ID and device ID
- Login session ID
- X-integrated token
- Google SSO email address
- Profile details
- Subscription information
- Billing status
- Usage statistics
The published data set also includes anonymous account records, although Gyazo has not disclosed what proportion of the exposed records they represent.
In a statement published earlier this week, Helpfeel said:
“Subsequent investigation confirmed that a third party had accessed Gyazo’s database and published user information and metadata related to uploaded images without permission.”
490 million image metadata records exposed
The breach also exposed approximately 490 million image metadata records. Most of the records relate to images uploaded to Gyazo before January 2019.
The exposed metadata may include:
- Image IDs used to construct image URLs
- Upload IP addresses
- User-agent strings
- EXIF location data
- OCR-extracted text
- Image titles
- Source URLs
- Hashed passphrases for private images
Helpfeel said image IDs can be used to access the corresponding content. As a result, the company has temporarily disabled access to files associated with records that were made public.
The attackers also obtained a list identifying private images. Gyazo said it cannot rule out the possibility that some of those images were viewed.
No evidence of data deletion or breaches of other Helpfeel services
Gyazo said its investigation found no indication that data was deleted during the incident. The company also said it found no evidence that data was stolen from other Helpfeel or Cosense services.
Helpfeel is investigating the incident with outside experts, contacting authorities, and directly notifying affected users.
What Gyazo users should do
Gyazo users should change their passwords on Gyazo and on any other services where they reused the same credentials. Users should also remain alert for suspicious emails, messages, login alerts, and other communications that may attempt to exploit the exposed account information.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



