Gyazo has confirmed a major data breach affecting approximately 23.62 million user records. Attackers exploited a server vulnerability and also accessed metadata linked to 490 million uploaded images.
Attackers Exploit Gyazo Server Vulnerability
Gyazo is a cloud-based screenshot and screen-recording platform operated by Helpfeel. The service automatically uploads captured media and creates shareable links.
The platform has gained particular popularity among gaming communities. It claims around 23 million users worldwide and has handled 3.1 billion media uploads.
According to Helpfeel, the security incident occurred on September 11, 2026. Attackers exploited a vulnerability to enter Gyazo’s database and access user information.
The company detected suspicious activity on September 12. It then fixed the vulnerability that enabled the intrusion.
However, the attackers had already obtained millions of records by that point.
Gyazo Suspends Service During Investigation
Helpfeel temporarily suspended the Gyazo service as a preventive measure while its teams conducted maintenance.
The company confirmed that an unauthorised third party accessed the database. The intruder obtained user information and metadata associated with uploaded images.
Gyazo has brought in external experts to investigate the incident. It has also contacted the relevant authorities and started notifying affected users directly.
However, the company has not disclosed how the attackers discovered or exploited the server vulnerability.
Breach Exposes 23.62 Million User Records
The exposed information varies between users. Therefore, not every affected account had the same types of data compromised.
The stolen records may include:
- Names and nicknames
- Email addresses
- Password hashes
- User and device identifiers
- Login session identifiers
- X integration tokens
- Google single sign-on email addresses
- Profile information
- Subscription details
- Billing status
- Usage statistics
The dataset also contains records linked to anonymous accounts. However, Gyazo did not reveal how many anonymous users the incident affected.
Password hashes do not reveal passwords directly. Nevertheless, attackers may attempt to crack weak passwords or reuse the information in other attacks.
Meanwhile, exposed session IDs and integration tokens may create additional risks. Attackers could potentially use valid tokens to access connected accounts or active sessions.
Image Metadata Records Also Compromised
The Gyazo data breach also exposed approximately 490 million image metadata records. Most of those records relate to images uploaded before January 2019.
The compromised metadata may contain image IDs, upload IP addresses and browser User-Agent strings. It can also include image titles, source URLs and location details stored in EXIF data.
Additionally, the database contained text that Gyazo’s optical character recognition system extracted from uploaded images.
Records for private images may include hashed passphrases. Furthermore, the attackers obtained a list that identified which images users had marked as private.
Image IDs Could Reveal Uploaded Content
Gyazo uses image IDs to construct the URLs for uploaded content. Therefore, someone with a valid image ID may potentially locate the corresponding screenshot or recording.
Because of this risk, Helpfeel temporarily disabled access to files connected with the exposed records.
The company also acknowledged that attackers may have viewed some private images. However, its investigation has not confirmed the full extent of any unauthorised image access.
Private screenshots can contain highly sensitive information. For example, users may capture login pages, private conversations, financial records or internal workplace systems.
Meanwhile, location information and extracted text could help attackers create more convincing phishing messages.
No Evidence of Deleted Data
Helpfeel found no evidence that the attackers deleted information during the incident. Therefore, the breach currently appears to involve unauthorised access and data theft rather than destructive activity.
The company also examined its other services. So far, investigators have found no evidence that attackers stole data from Helpfeel or Cosense platforms outside Gyazo.
Nevertheless, the investigation remains active. Further findings may provide more information about the intrusion and the affected records.
Users Should Change Reused Passwords
Gyazo advises all users to change their account passwords. Users should also update passwords on any other platform where they reused the same credentials.
Moreover, affected users should monitor their accounts for unfamiliar login attempts or unexpected changes. They should also treat emails about the Gyazo data breach with caution.
Attackers may use exposed names, email addresses and account information to create targeted phishing messages. Consequently, users should avoid opening unexpected links or attachments.
Anyone who connected Gyazo to an X account should review active integrations and revoke unfamiliar sessions. Users should also inspect their Google accounts for suspicious access if they used Google single sign-on.


0 responses to “Gyazo Data Breach Exposes 23.6 Million User Records”