A vulnerability in the upload server of popular screenshot platform Gyazo has led to one of the largest data breaches of 2026, exposing 23.62 million user records and metadata from roughly 490 million images. The Japanese parent company Helpfeel confirmed the breach on September 16 after an attacker exploited the flaw to execute arbitrary commands on backend systems and access the platform’s database.
What Happened
Gyazo is a cloud-based screenshot and screen-recording tool used by approximately 23 million people worldwide. The service automatically uploads captures to the cloud and generates shareable links — a workflow especially popular among gamers, developers, and remote teams. The platform hosts over 3.1 billion media items.
On the evening of September 11, 2026 (Japan time), Helpfeel’s security team detected suspicious activity on Gyazo’s infrastructure. By early the next morning, they had identified the attack vector: a vulnerability in the image upload server that allowed the attacker to run arbitrary commands on Helpfeel’s systems. The company blocked the access routes, severed the attacker’s connections, and patched the vulnerability on September 12.
But the damage was already done. The attacker had accessed and exfiltrated a vast trove of user data from Gyazo’s database before the team could intervene.
What Was Stolen
The breach compromised two distinct datasets. The first — affecting all 23.62 million user accounts — includes email addresses, password hashes, user and device IDs, login session IDs, X (formerly Twitter) integration tokens, Google SSO email addresses, profile details, subscription and billing status, registration and last login dates, and usage statistics. Helpfeel noted that these records include anonymous accounts, so the number of identifiable individuals may be lower. Importantly, no credit card or payment information was exposed.
The second dataset is arguably more concerning. Approximately 490 million image metadata records were stolen, containing image IDs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text from screenshots, image titles, source URLs, and hashed passphrases for password-protected private images. This metadata primarily covers images uploaded before January 2019, representing about 14.4% of Helpfeel’s total image data, though an additional 2.4 million records were pulled using separate filtering criteria.
The Privacy Risk No One Expected
What makes this breach especially dangerous is a design quirk baked into how Gyazo handles image privacy. Gyazo relies on link obscurity for access control — each image gets a 32-character alphanumeric ID embedded in its URL, and the assumption is that this ID cannot be guessed. But with 490 million image IDs now in the hands of the attacker, that obscurity is gone. Anyone with the leaked metadata can reconstruct valid Gyazo image URLs and potentially view the corresponding screenshots.
Helpfeel acknowledged it “cannot rule out the possibility that the third party may have viewed some private images.” For users who relied on Gyazo to share screenshots of sensitive material — internal dashboards, credentials, private conversations, medical records, or financial data — this exposure is a serious concern. The leaked EXIF data, which can include GPS coordinates, and OCR-extracted text, which can reveal the actual content of screenshots, amplify the risk considerably.
Helpfeel’s Response and the Delayed Disclosure
The timeline of Helpfeel’s response has drawn scrutiny. While the company detected and patched the vulnerability within roughly 12 hours — a commendably fast technical response — the disclosure timeline was slower. After confirming data theft on September 14, Helpfeel reported the incident to Japan’s Personal Information Protection Commission on September 15 and published a public breach notice on September 16. During the interim, service disruptions were described to users as “emergency maintenance” rather than a security incident.
The company has since taken several remediation steps: invalidating and restricting affected authentication tokens, temporarily suspending image viewing to prevent unauthorized access via leaked IDs, engaging external forensic specialists, and resuming the image upload service on September 15. No threat actor has been publicly identified, and the investigation is ongoing.
Who Is Affected
Any current or former Gyazo user should assume their account data was exposed. The platform’s 23 million user base spans multiple countries, though it has a particularly strong presence in Japan, the United States, and Europe. Users of paid Gyazo Pro and Gyazo Teams plans face additional risk, since private image features — “Only me” visibility and password-protected captures — are paid-tier features, and the breach may have compromised the hashed passphrases protecting those images.
Enterprise and team users should also evaluate whether sensitive internal screenshots shared through Gyazo’s collaboration features may have been exposed via the leaked image metadata.
What You Should Do Now
If you have a Gyazo account, here are the immediate steps to take:
Change your password immediately — and update the password on any other service where you reused it. The stolen password hashes could be cracked offline, especially if the hashing algorithm is weak.
Revoke connected app tokens. If you linked Gyazo with your X (Twitter) or Google account, rotate or revoke those integration tokens through each platform’s security settings.
Audit your screenshot history. Think about what you have captured and shared via Gyazo. If any screenshots contained passwords, API keys, tokens, internal URLs, or personally identifiable information, treat those as compromised and rotate them.
Watch for targeted phishing. With email addresses, usage data, and even OCR-extracted text from screenshots in the attacker’s hands, phishing campaigns can be highly personalized. Be skeptical of unexpected emails referencing your Gyazo usage or screenshots.
Monitor your accounts. Enable multi-factor authentication wherever possible, and watch for unusual login activity on accounts associated with your Gyazo email address.
The Bigger Picture
This breach underscores a risk that security teams have long warned about: screenshot and clipboard-sharing tools are often invisible vectors for data exposure. Unlike files stored in managed enterprise environments, screenshots captured by tools like Gyazo sit outside most organizations’ data governance and DLP frameworks. Users routinely screenshot sensitive information without thinking of it as data exfiltration — yet a breach like this one effectively turns years of casual captures into a searchable intelligence goldmine.
For security leaders, this is a reminder to audit which screenshot and screen-recording tools employees are using, whether those tools store data in the cloud, and whether that data falls under the organization’s security policies. For individual users, the lesson is simpler: treat every screenshot as if it could one day become public, and periodically purge captures you no longer need.
Sources: BleepingComputer, The Hacker News, Helpfeel Official Notice, CyberInsider
Leave a comment