Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
Security· 3 min read

Gyazo breach: server flaw exploited, 23.6 million records stolen

Gyazo has confirmed the theft of some 23.62 million user records after a server flaw was exploited on 11 September 2026. The service is suspended, and 490 million image metadata records are also affected.

Illustration of a compromised screenshot-sharing service: a stack of captured images escaping from a breached server.

Gyazo, the screenshot and screen-recording tool operated by Japanese company Helpfeel, has confirmed it was breached. The facts were reported on 18 September 2026 by Bleeping Computer, drawing on the announcements published by the company. That is the only source available to us to date: everything below comes from Gyazo’s own communications as relayed by that outlet.

A week between the intrusion and the announcement

According to the company, the incident took place on 11 September 2026: attackers exploited a server vulnerability that gave them access to the database. Suspicious activity was detected the next day, 12 September, and the flaw that was used has been patched — but the data had already been exfiltrated.

The platform was then taken offline as a precaution, for the duration of a maintenance window. Gyazo claims 23 million users worldwide and 3.1 billion media files uploaded, and is especially widespread in gaming communities. The volume stolen, roughly 23.62 million records, is therefore on the same order of magnitude as the entire database.

What the user records contain

What was exposed varies from one account to another. Based on the company’s investigation, a record may contain one or more of the following: name or nickname, email address, password hash, user and device identifiers, login session identifiers, X integration tokens, the email address tied to Google authentication, profile details, subscription information, billing status and usage statistics.

Anonymous accounts are also in the batch; Gyazo has not said what share of the total they represent.

The second part: 490 million image metadata records

The incident also exposed 490 million metadata records attached to images, most of them linked to uploads predating January 2019. They include the image identifiers used to build sharing URLs, the IP addresses used at upload time, User-Agent strings, EXIF location data, text extracted by OCR, image titles, source URLs, and hashes of the passphrases protecting private images.

Helpfeel notes that these image identifiers can allow access to the corresponding content: access to the files whose records were exposed has therefore been temporarily disabled. The company also states that the attackers obtained a list identifying private images, and that it cannot rule out that some of them were viewed.

The investigation found no sign of data deletion, nor any element indicating theft from the publisher’s other services, Helpfeel and Cosense.

What you can do

Gyazo recommends that all of its users change their password on the service, as well as on any other platform where the same credentials were reused — that is the precaution that matters most once password hashes are in circulation. The company also calls for vigilance regarding suspicious communications.

It says it is notifying affected individuals directly, conducting its investigation with external experts, and that it has contacted the authorities.

A service that has been putting your screenshots online for years holds an archive that nobody keeps a full inventory of in their head. That archive, and not just a password, is what is at stake here.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.