Gyazo Breach Exposes 23.6 Million User Records and 490 Million Image Metadata Records

Gyazo, a cloud service for sharing screenshots and images, has disclosed a data breach affecting about 23.62 million user records. Helpfeel, the company that operates Gyazo, published a notice about the incident on September 16, 2026, and BleepingComputer reported on it on September 18.

What happened

According to Helpfeel's notice, the company detected suspicious activity on the evening of September 11, 2026, and had blocked the access routes by early on September 12. BleepingComputer reported that the attacker exploited a vulnerability on a Gyazo server.

"Our subsequent investigation confirmed that the third party had accessed Gyazo's database and that user information and metadata associated with uploaded images had been disclosed without authorization," the company said, according to BleepingComputer.

What was exposed

Helpfeel said the user data included names, email addresses, password hashes, user IDs, device IDs, session IDs, social media integration tokens, profile information, subscription details and billing status. BleepingComputer reported that the integration tokens included tokens for X, and that Google sign-in email addresses were also exposed.

The breach also covered about 490 million image metadata records. According to Helpfeel, these mainly relate to images uploaded before January 2019. The metadata includes image IDs, the IP addresses images were uploaded from, EXIF location data, text extracted from images by OCR, image titles and hashed passphrases for private images.

Helpfeel stressed two limits on the breach. "We have confirmed that no payment information, including credit card numbers, was disclosed without authorization," the company said. It added that "our investigation to date has not confirmed any loss of image data."

The company's response

According to BleepingComputer, Helpfeel took the platform offline for maintenance, fixed the exploited flaw, disabled access to exposed files, notified affected users and authorities, and brought in outside experts to investigate. Helpfeel said Gyazo was suspended from September 24 to 27 for security maintenance and has since resumed operations.

The company is advising users to change their Gyazo passwords right away, to change passwords on any other services where they used the same one, and to watch for suspicious messages.

Why it matters

Screenshot tools often capture private information, so image metadata such as location data and text pulled from images can reveal more than a typical account record. Even though the passwords were stored as hashes, people who reused their Gyazo password elsewhere are at risk if those hashes are cracked. The exposed session IDs and integration tokens are another reason for users to sign out and reset their credentials.


Sources

This article was drafted with AI assistance and checked against the sources above. Company claims are reported as claims. Cover image is AI-generated.