Gyazo discloses a breach of 23.6 million user records and image metadata
EditorialBy TrustList Editorial
Helpfeel, which operates Gyazo, said on 16 September 2026 a server flaw let an attacker access about 23.6 million user records and 490 million image-metadata records, including password hashes and tokens; it is asking every user to change their password.
About Gyazo discloses a breach of 23.6 million user records and image metadata
Gyazo discloses a breach of 23.6 million user records and image metadata
16 September 2026 — Helpfeel, the company that operates the screenshot and image-hosting service Gyazo, said in its own notice on 16 September 2026 that a third party exploited a vulnerability in Gyazo's image-upload server on 11 September to gain unauthorized access and execute arbitrary commands. Helpfeel detected the activity the next day and fixed the vulnerability, but by then the data had already been copied. The company describes the scale in its own statement: about 23.62 million records of Gyazo user data, and about 490 million metadata records tied mainly to images registered in or before January 2019.
What Gyazo's own notice says was taken
- User records including names, email addresses, password hashes, user and device IDs, and authentication tokens tied to third-party sign-in (the notice names X integration tokens specifically).
- Image metadata: image IDs, the IP addresses associated with uploads, and text Gyazo's systems had extracted from images — not the image files' visual content itself, according to the notice.
- Helpfeel says it has taken parts of the platform offline for maintenance while it works through the incident.
What Gyazo is telling users to do
- Change your Gyazo password, and change the password anywhere else you reused it, which Helpfeel's own notice asks for directly.
- If your account is linked to a third-party sign-in such as an X (formerly Twitter) integration, treat that connection as potentially exposed and review or revoke it from the other service's side.
- If your team uses Gyazo for business screenshots or documentation — support tickets, bug reports, internal wikis — check whether any exposed image metadata or extracted text could reveal internal URLs, credentials shown on screen, or other sensitive content captured in old screenshots, since the exposed metadata reaches back to images from 2019 and earlier.
Sources
- Helpfeel's own notice: Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo — 16 September 2026
- BleepingComputer: Gyazo server flaw exploited to steal 23.6 million user records — 21 September 2026
- Help Net Security: Hackers exploit Gyazo server flaw to steal 23.6 million user records — 21 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.