Gyazo data breach exposes 23.6 million users after server vulnerability exploited

Popular screenshot platform taken offline; image metadata and user credentials compromised

edit
By LineZotpaper
Published
Read Time2 min
The Gyazo image-sharing platform has confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026, stealing approximately 23.6 million user records. The company took the service offline for maintenance and has urged users to change passwords.

Gyazo, a cloud-based screenshot and screen-recording tool operated by Helpfeel, disclosed the breach in a statement published earlier this week. The platform is especially popular in gaming communities and claims 23 million users worldwide, who have submitted over 3.1 billion media items.

According to the company, the incident occurred on September 11, allowing attackers to access its database and obtain approximately 23.62 million user records. The company detected suspicious activity on September 12 and fixed the vulnerability, but the data had already been stolen.

The exposed data varies per user and may include names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, and usage statistics.

Additionally, the breach exposed 490 million image metadata records, most associated with images uploaded before January 2019. These metadata include image IDs used to construct image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Helpfeel noted that image IDs could potentially be used to access the corresponding content, and the company has temporarily disabled access to files whose records were exposed. The hackers also obtained a list identifying private images, and the company cannot rule out that some were viewed.

Gyazo has taken the platform offline for maintenance as a preventive measure. The company is notifying affected users directly and conducting an investigation with external experts. Authorities have been contacted. No evidence was found that data was deleted, and Helpfeel's other services (Helpfeel and Cosense) were not affected.

All Gyazo users are advised to change their passwords on the service and on other platforms where they use the same credentials, and to remain alert for suspicious communications.

§

Analysis

Why This Matters

  • Approximately 23 million users may have had their personal information, including password hashes and login session IDs, compromised, risking account takeover and identity theft.
  • The exposure of 490 million image metadata records, including EXIF location data and OCR text, poses serious privacy risks for users, especially those with private or sensitive images.
  • The breach highlights ongoing vulnerabilities in cloud-based platforms that handle large volumes of user-generated content, emphasizing the need for robust server security.

Background

Gyazo is a cloud-based screenshot and screen-recording tool operated by Helpfeel. It automatically uploads user screen captures to the cloud and provides a shareable link, making it popular in gaming and online communities. The platform has been operating for over a decade and stores billions of media items. This is a significant breach affecting nearly the entire user base.

Key Perspectives

Gyazo/Helpfeel: The company has acknowledged the breach, temporarily suspended the service, fixed the vulnerability, and is notifying users while working with external experts and authorities. It advises users to change passwords. Affected Users: Users face risks from exposed credentials, potential phishing attacks, and compromise of private images and location data. Many may need to reset passwords across multiple services. Security Researchers: The breach underscores the importance of timely vulnerability patching and the risks of storing extensive metadata, including EXIF and OCR data, that can be exploited.

What to Watch

  • Evidence of the stolen data being offered for sale or leaked on dark web forums or data breach marketplaces.
  • Any further disclosure from Gyazo about the root cause of the server vulnerability.
  • User response: how many change passwords and whether any secondary attacks emerge.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.