Gyazo Confirms Major Data Breach Affecting 23.6 Million Users
The popular image-sharing platform **Gyazo**, operated by **Helpfeel**, has confirmed a significant data breach impacting approximately 23.6 million user records. Attackers exploited a server vulnerability, gaining unauthorized access to sensitive user information and metadata associated with millions of uploaded images. The platform is currently offline for maintenance as **Helpfeel** investigates the incident.

**Gyazo**, a widely used cloud-based screenshot and screen-recording tool, has disclosed a substantial data breach. The incident, which occurred on September 11, 2026, allowed unauthorized parties to access **Gyazo**'s database and exfiltrate roughly 23.62 million user records.
### The Breach Details
**Helpfeel**, the company behind **Gyazo**, detected suspicious activity on September 12, 2026. While the exploited vulnerability was swiftly patched, the attackers had already managed to steal a significant volume of data. **Gyazo** confirmed in a statement that a third party accessed their database, leading to the unauthorized disclosure of user information and image metadata.
As a direct consequence, the **Gyazo** service has been temporarily suspended for maintenance, a proactive measure to secure the platform and facilitate ongoing investigations.
### Exposed User Data
The compromised data varies per user but may include a range of personal and account-related details:
* Names/nicknames
* Email addresses
* Password hashes
* User and device IDs
* Login session IDs
* **X** integration tokens
* **Google** SSO email addresses
* Profile details
* Subscription information
* Billing status
* Usage statistics
**Gyazo** also noted that the exposed dataset includes anonymous account records, though the exact percentage was not disclosed.
### Image Metadata and Privacy Concerns
Beyond user records, the breach exposed approximately 490 million image metadata records, predominantly from images uploaded before January 2019. This metadata encompasses sensitive information such as:
* Image IDs (used to construct image URLs)
* Upload IP addresses
* User-Agent strings
* EXIF location data
* OCR-extracted text
* Image titles
* Source URLs
* Hashed passphrases for private images
**Helpfeel** has acknowledged that image IDs could potentially be used to access corresponding content. Consequently, access to files whose records were exposed has been temporarily disabled. The company also cannot rule out the possibility that some private images, identified through a list obtained by the hackers, may have been viewed.
### Ongoing Investigation and Recommendations
The company's investigation has not found evidence of data deletion or compromise of its other services, **Helpfeel** and **Cosense**. **Gyazo** is actively notifying affected users, collaborating with external experts, and has engaged with relevant authorities.
All **Gyazo** users are strongly advised to immediately change their passwords on the service. Furthermore, users should update passwords on any other platforms where they may have reused the same credentials. Vigilance against suspicious communications, such as phishing attempts, is also crucial in the wake of this incident.