← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

🔄 Updated 5d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 23.62 million user records exposed, including email addresses and password hashes.
  • 490 million image metadata records exposed, mostly from before January 2019.
  • Attacker gained access via a vulnerability in Gyazo's image upload server.
  • Users advised to change passwords and monitor for suspicious activity.
  • Helpfeel owns Gyazo.
  • Attacker accessed user records on September 11.
  • Compromised user information includes names, user/device IDs, X integration tokens, profile info, usage stats, and billing info.
  • Payment card information was not compromised.
  • 23.62 million affected records include anonymous accounts.
  • Gyazo is a cloud-based screenshot and screen-recording tool.
  • Gyazo has 23 million users worldwide.
  • Users have submitted 3.1 billion media items to Gyazo.
  • Gyazo service was temporarily suspended for maintenance.
  • Company detected suspicious activity on September 12.

Security Breach Details

Gyazo, an image-sharing service operated by Helpfeel, announced a security breach that compromised approximately 23.62 million user records. The exposed data includes email addresses, password hashes, user IDs, device IDs, login session IDs, and other profile information. Additionally, about 490 million image metadata records, primarily from images uploaded before January 2019, were exposed. These metadata records include image IDs that could allow unauthorized viewing of images.

Method of Attack and Exposed Data

The attacker exploited a vulnerability in Gyazo's image upload server, which allowed them to execute arbitrary commands on Helpfeel's systems and access Gyazo's database. Helpfeel confirmed that no payment information, such as credit card numbers, was exposed. The exposed user records vary by user but can include names, email addresses, password hashes, user IDs, device IDs, login session IDs, X (formerly Twitter) integration tokens, Google SSO email addresses, profile information, language preferences, registration and last login dates, subscription plans, and billing status (without payment details).

User Impact and Recommendations

The exposure of image IDs means that some private images could be viewed without permission, leading Helpfeel to temporarily disable viewing for certain images. Helpfeel has urged all Gyazo users to change their passwords immediately and to update passwords on any other services where they might have reused the same or similar credentials. Users are also advised to be vigilant for suspicious emails or messages related to this incident. While 23.62 million records were exposed, Helpfeel is still determining the exact number of individuals whose personal information was compromised, as the count includes anonymous accounts without registered email addresses.

Mitigation Efforts

Helpfeel stated it has reviewed the exposed authentication data and implemented necessary measures, including invalidation and restrictions, though specific invalidated items were not detailed. Gyazo typically uses a verification code for logins from new IP addresses, but it is unclear if exposed session IDs remain valid. The company's help pages previously stated that Gyazo image links, built from 32-character IDs, are secure enough that they "can't be guessed," but the breach indicates a compromise of this privacy mechanism.

Updates

🕒 2026-09-18 · new reporting from BleepingComputer
  • Gyazo is a cloud-based screenshot and screen-recording tool.
  • Gyazo has 23 million users worldwide.
  • Users have submitted 3.1 billion media items to Gyazo.
  • Gyazo service was temporarily suspended for maintenance.
  • Company detected suspicious activity on September 12.
🕒 2026-09-18 · new reporting from SecurityWeek
  • Helpfeel owns Gyazo.
  • Attacker accessed user records on September 11.
  • Compromised user information includes names, user/device IDs, X integration tokens, profile info, usage stats, and billing info.
  • Payment card information was not compromised.
  • 23.62 million affected records include anonymous accounts.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Gyazo image-sharing platform confirmed a data breach on September 11, 2026, where attackers exploited a server vulnerability to steal approximately 23.6 million user records and 490 million image metadata records. This incident impacts a large user base, particularly in gaming communities, and exposes sensitive user information and image-related data, leading to the temporary suspension of the service.

Helpfeel's Gyazo image-sharing service experienced a data breach where hackers exploited a vulnerability to access approximately 23.6 million user records and 490 million image metadata records. This incident compromises user privacy and could lead to further exploitation of user data and image URLs.

Gyazo, an image-sharing service, experienced a security breach that exposed approximately 23.62 million user records, including email addresses and password hashes, along with 490 million image metadata records. This incident is significant because it compromises user privacy and security, potentially allowing unauthorized access to images and other services if users reused passwords.