Skip to main content
Emerging ThreatsData Breaches

Gyazo Breach Exposes 23.6 Million User Records After Server Flaw Exploited

Server room interior with technicians working on equipment, one server rack highlighted.

"Currently, the Gyazo service is temporarily suspended for maintenance as a preventive measure. We sincerely apologize for any inconvenience caused. Please wait a little longer until recovery," reads a post on X.

Helpfeel's Gyazo: scale and scope of the intrusion

Gyazo, a cloud-based screenshot and screen-recording platform operated by Helpfeel, confirmed that attackers exploited a server vulnerability and accessed its database on September 11, 2026. The company says approximately 23.62 million user records were stolen and that the exposed dataset also includes 490 million image metadata records, most tied to uploads made before January 2019. Gyazo says the platform claims 23 million users and stores about 3.1 billion media items.

Timeline: discovery, fix, and shutdown

According to Gyazo, the suspicious activity was detected on September 12, 2026. The company says it fixed the vulnerability the attackers used after detection, but that the data had already been taken. As a preventive step, Gyazo has taken the service offline and posted the maintenance notice on X. Helpfeel reports it is conducting an investigation with external experts and has contacted the authorities; affected users are being notified directly.

What data was exposed

Helpfeel's statement lists the categories of user information and metadata that may have been disclosed "without authorization." The company says exposed user data may include one or more of these fields:

  • Names and nicknames
  • Email addresses and Google SSO email addresses
  • Password hashes
  • User and device IDs
  • Login session IDs and X integration tokens
  • Profile details, subscription information, and billing status
  • Usage statistics

Separately, the 490 million image metadata records the company identified include image IDs used to construct image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Helpfeel notes image IDs can potentially be used to access corresponding content and that it has temporarily disabled access to files whose records were exposed.

Private images, deletion, and other services

Helpfeel says the attackers also obtained a list identifying private images and that the company "cannot rule out" that some private images were viewed. The firm reported no signs that data were deleted in the incident. It also stated that its investigation has found no evidence that other Helpfeel and Cosense services had data stolen.

What this means for Gyazo users, security teams, and threat actors

  • Gyazo users: Helpfeel is advising all users to change their passwords on Gyazo and on any other services where the same credentials are used, and to remain alert for suspicious communications. Users whose accounts or image records were part of the exposed sets will receive direct notification, the company says.
  • Security teams at organizations that allow Gyazo use: the exposure of image metadata—including OCR text, EXIF location data, and source URLs—raises specific concerns about leaked operational or sensitive information embedded in images. Helpfeel's disabling of exposed files is a containment step organizations will need to reconcile with their own incident response processes.
  • Threat actors: the combination of account-related fields (email addresses, session IDs, integration tokens) with extensive image metadata creates opportunities for credential-stuffing, session hijacking, or content harvesting if attackers leverage the stolen records.

Gyazo's published account establishes a firm set of facts: attackers exploited a server vulnerability, 23.62 million user records and 490 million image metadata records were taken, the company fixed the vulnerability after detection, and the service is offline while Helpfeel investigates with external experts and notifies authorities and affected users. The company has disabled access to files tied to exposed records and is urging password changes and vigilance for suspicious messages.

Several concrete questions remain in the record the company has released: what percentage of accounts were anonymous, which private images—if any—were viewed, and how long the service will remain suspended. For now, Helpfeel's notice on X and its direct notifications to affected users are the active steps the company has taken while external experts and authorities investigate.

Original story