Image-sharing platform Gyazo hit by breach affecting 23.6 million accounts

Gyazo, a cloud-based screenshot service operated by Helpfeel, disclosed a data breach that occurred on September 11, 2026, after attackers exploited a server vulnerability. The incident exposed approximately 23.62 million user records, including email addresses, password hashes, and session IDs, as well as metadata for 490 million uploaded images. The company has temporarily suspended the service while it investigates and fixes the underlying flaw.
The breach targeted Gyazo's core database, where account credentials and image metadata are stored. The platform's popularity among gaming communities means a substantial portion of its 23 million registered users may be affected. The company detected the intrusion the day after it occurred and patched the exploited server flaw, though data had already been exfiltrated by that point.
Exposed metadata spans roughly half a billion image records, predominantly from uploads predating January 2019. This includes technical details like IP addresses, device identifiers, and EXIF location data, along with OCR-extracted text and source URLs. Gyazo has temporarily restricted access to affected files while assessing whether private images were compromised.
This breach could have wide-reaching effects given Gyazo's large user base and the sensitivity of the data involved. Password hashes and session IDs may enable account takeover attempts, while exposed image metadata — including location data and OCR text — could raise privacy concerns for individuals who captured sensitive information in screenshots. The inclusion of private image identifiers means some users may face exposure of content they believed was secured. Affected users could experience phishing, credential stuffing, or targeted social engineering in the coming months.