Skip to content

Gyazo Breach Exposes 23.6 Million Accounts and 490 Million Image Records

Helpfeel confirmed on September 16, 2026 that attackers exploited a Gyazo image-upload server flaw on September 11 to steal roughly 23.62 million user.

By THEYDIDNTASK
Gyazo Breach Exposes 23.6 Million Accounts and 490 Million Image Records
Gyazo Breach Exposes 23.6 Million Accounts and 490 Million Image Records

TL;DR

  • —Gyazo is the quiet utility millions of people use without thinking: screenshot a portion of your screen, and it returns a short uploaded link you can share.
  • —According to Helpfeel's account, an attacker exploited a vulnerability in Gyazo's image-upload server on September 11, 2026.
  • —The flaw let the intruder upload malicious files and execute arbitrary commands on the underlying system.
The Breach Gyazo is the quiet utility millions of people use without thinking: screenshot a portion of your screen, and it returns a short uploaded link you can share. That means it quietly holds a lot of what ends up on a screen — and, for older uploads, the metadata baked into the images people grabbed. According to Helpfeel's account, an attacker exploited a vulnerability in Gyazo's image-upload server on September 11, 2026. The flaw let the intruder upload malicious files and execute arbitrary commands on the underlying system. From there the attacker moved into the account and image-metadata database. Helpfeel says it detected suspicious activity the same evening and cut off access by September 12 — but by then the database had been read and, per multiple reports, copied. 23.62 Million Accounts, 490 Million Image Records Helpfeel's own language is precise: "approximately 23.62 million records containing data related to Gyazo users were disclosed without authorization." Separately, around 490 million records of image metadata were exposed — the bulk tied to images uploaded in January 2019 or earlier, meaning some exposed data had sat in Gyazo's systems for roughly seven years. The exposed dataset splits into two buckets: Account records: names, email addresses, hashed passwords, user and device IDs, login session IDs, X integration tokens, billing status (not card numbers), and usage statistics. Image metadata: image IDs used to construct image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Helpfeel explicitly states no payment card numbers were part of the breach. But it also warns that image IDs can potentially be used to access the corresponding content — which is why the company temporarily disabled access to files whose records were exposed, suspended the service for maintenance, and said it cannot rule out that some private images were viewed. Why This One Hurts A breach of email-and-hash data is bad. A breach that also exposes EXIF location data and thumbnails of private images is categorically worse, because it connects what you screenshot to where you were when you took it. For anyone who screenshots sensitive work material, financial documents, or personal messages through Gyazo, the exposure isn't a login credential — it's the content of the images themselves leaking into an attacker's hands. That's the same failure mode we documented around browser fingerprinting and the invisible trail and image metadata in privacy guides: images carry far more than pixels. Tools that strip or warn about EXIF exist for a reason, and warehouse-ing hundreds of millions of them in a single reachable database is how a convenience tool becomes a surveillance liability. What to Do Treat your email + hashed password as exposed. If you reused your Gyazo password anywhere, change it immediately — hashes are crackable, especially weak ones. Password managers make this the regular habit it needs to be. Invalidate sessions. Log out of Gyazo everywhere. Session IDs that fell into the dump can be used to impersonate you until they're rotated. Assume older uploads are compromised. If you posted a screenshot before 2019 through Gyazo, assume its metadata — including location — is out there. Rotate any private-image passphrases you used. Audit what you screenshot. A screenshot of a document is a copy of that document. Prefer tools that keep content and processing on-device, and delete uploads you no longer need. The Pattern Gyazo is the latest reminder that stored data is a liability, not an asset. A free, convenient screenshot tool held 490 million image-metadata records on a single reachable server. The scale is striking, but the shape is familiar: a utility that hoards intimate data, defended by a single vulnerable upload path, sending tens of millions of users scrambling to log out. The practical lesson is unchanged — the tool that holds your screenshots is the tool most worth locking down — and the safest screenshot is the one that never leaves your device in the first place.