Skip to content
TrustList
News

Gyazo discloses a breach of 23.6 million user records and image metadata

Editorial

By TrustList Editorial

Helpfeel, which operates Gyazo, said on 16 September 2026 a server flaw let an attacker access about 23.6 million user records and 490 million image-metadata records, including password hashes and tokens; it is asking every user to change their password.

About Gyazo discloses a breach of 23.6 million user records and image metadata

Gyazo discloses a breach of 23.6 million user records and image metadata

16 September 2026 — Helpfeel, the company that operates the screenshot and image-hosting service Gyazo, said in its own notice on 16 September 2026 that a third party exploited a vulnerability in Gyazo's image-upload server on 11 September to gain unauthorized access and execute arbitrary commands. Helpfeel detected the activity the next day and fixed the vulnerability, but by then the data had already been copied. The company describes the scale in its own statement: about 23.62 million records of Gyazo user data, and about 490 million metadata records tied mainly to images registered in or before January 2019.

What Gyazo's own notice says was taken

  • User records including names, email addresses, password hashes, user and device IDs, and authentication tokens tied to third-party sign-in (the notice names X integration tokens specifically).
  • Image metadata: image IDs, the IP addresses associated with uploads, and text Gyazo's systems had extracted from images — not the image files' visual content itself, according to the notice.
  • Helpfeel says it has taken parts of the platform offline for maintenance while it works through the incident.

What Gyazo is telling users to do

  • Change your Gyazo password, and change the password anywhere else you reused it, which Helpfeel's own notice asks for directly.
  • If your account is linked to a third-party sign-in such as an X (formerly Twitter) integration, treat that connection as potentially exposed and review or revoke it from the other service's side.
  • If your team uses Gyazo for business screenshots or documentation — support tickets, bug reports, internal wikis — check whether any exposed image metadata or extracted text could reveal internal URLs, credentials shown on screen, or other sensitive content captured in old screenshots, since the exposed metadata reaches back to images from 2019 and earlier.

Sources