
Image sharing platform Gyazo has confirmed that a data breach has occurred after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
Gyazo is a cloud-based screenshot and screen recording tool from Helpfeel that automatically uploads users’ screenshots to the cloud and provides them with a shareable link for sharing in chats, forums, social media, etc.
It is particularly popular in gaming communities and claims 23 million users worldwidewho submitted 3.1 billion media articles.
According to a statement from the company, the incident occurred on September 11, 2026 and allowed attackers to access the company’s database and retrieve approximately 23.62 million user records.
The company has now taken the platform offline for maintenance.
“Currently, the Gyazo service is temporarily suspended for maintenance as a preventative measure. We sincerely apologize for any inconvenience. Please wait a little longer for restoration.” reads a post on X.
The company discovered the suspicious activity on September 12 and fixed a vulnerability that the attackers used to break into the platform. However, by this point the data had already been stolen.
“Our subsequent investigation confirmed that the third party accessed Gyazo’s database and that user information and metadata associated with uploaded images were disclosed without permission.” Gyazo confirmed in a statement Published earlier this week.
Based on Gyazo’s research, the data disclosed varies by user and may include one or more of the following:
- Names/nicknames
- Email addresses
- Password hashes
- User and device IDs
- Login session IDs
- X integration token
- Google SSO email addresses
- Profile details
- Subscription Information
- Billing status
- Usage statistics
The dataset disclosed includes anonymous account records, but Gyazo did not share what percentage these represent.
The platform also said the incident exposed 490 million image metadata records, most of which were related to images uploaded to the service before January 2019.
This metadata includes image IDs used to create image URLs, upload IP addresses, user agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images.
Helpfeel points out that image IDs may be used to access the corresponding content, which is why the company has temporarily blocked access to files whose records have been exposed.
In addition, it said the hackers also obtained a list of private images and the company could not rule out that some were viewed.
The company said its investigation found no evidence that data was deleted as a result of this incident.
The company also found no evidence that data was stolen from its other Helpfeel and Cosense services.
The company is notifying affected users directly while they conduct an investigation with outside experts and have contacted authorities.
All Gyazo users are advised to change their passwords on the service and on other platforms where they use the same credentials and to be alert for suspicious communications.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL and Atlassian for a two-hour digital summit to learn what attacks are changing at AI speed, what defenders should give up, and how to validate, decide, fix and re-validate at machine speed.

