data-breach โ€ข BleepingComputer

Gyazo Confirms Major Data Breach: 23.6 Million Records and 490 Million Image Metadata Exposed

Japanese developer Helpfeel has confirmed a major security incident compromising screenshot service Gyazo after adversaries exploited a server flaw. The investigation identified roughly 23.62 million user records alongside metadata for 490 million historical images created before January 2019, exposing emails, salted password hashes, IP addresses, and OCR text extracts.

Gyazo Confirms Major Data Breach: 23.6 Million Records and 490 Million Image Metadata Exposed

The popular visual capture and screenshot utility Gyazo, operated by Japanese developer Helpfeel, has confirmed a massive data breach after adversaries compromised one of its central image processing servers. Unauthorized activity was detected on September 11, 2026, following alerts indicating malicious script execution and anomalous command handling at the application layer.

A forensic investigation revealed that the intruders exfiltrated a database containing roughly 23.62 million user account records, including registered emails, salted and hashed passwords, and internal session identifiers. Digital investigators emphasize that 23.62 million records does not automatically translate to 23.62 million unique individuals; the dataset contains legacy records, test accounts, and multiple entries corresponding to individual active users.

However, the most privacy-sensitive dimension of the incident involves the vast repository of exposed metadata. Intruders acquired metadata archives detailing approximately 490 million screenshots and uploaded images created prior to January 2019. This metadata encompasses originating IP addresses at the moment of upload, exact timestamps, geographical data from EXIF tags, and text snippets generated via automated OCR.

Because software engineers, corporate staff, and IT support personnel routinely capture screens featuring error logs, configuration screens, and internal dashboards, the exposure of OCR-parsed text poses a serious secondary risk. Internal hostnames, private staging URLs, and embedded API tokens could be exposed to adversaries. Helpfeel has isolated the affected server, patched the remote upload vulnerability, and initiated direct notification campaigns to impacted customers.

Actionable Guidance for IT and Security Teams

  • Reset Credentials Immediately: Any user maintaining an active or dormant Gyazo account should change their password immediately and verify that identical passwords are not shared across enterprise services.
  • Audit Exposed Secrets in Visual Artifacts: Enterprise security teams should determine whether developers previously shared screenshots of production environments, rotating any API keys, database connection strings, or access tokens depicted in historical uploads.
  • Analyze Ingress and Egress Telemetry: SOC analysts should review corporate firewall and proxy logs for atypical outbound data volumes directed toward Gyazo storage endpoints.
  • Enforce Multi-Factor Authentication: Implement MFA across all primary email services linked to third-party tooling to mitigate credential-stuffing follow-up attacks.

Evidence Status

  • Confirmed: Helpfeel released an official advisory confirming unauthorized access affecting 23.62 million records and 490 million image metadata entries.
  • Reported: BleepingComputer and SecurityWeek verified the incident timeline and identified the initial entry vector as an unauthenticated file processing flaw.
  • Unconfirmed: Whether threat actors successfully archived the underlying raw image assets or solely exfiltrated the metadata tables remains under active investigation.

In Brief

  • Screenshot provider Gyazo suffered a major data breach impacting 23.62 million database records.
  • Metadata associated with 490 million historical images created before 2019 was exposed, including OCR text and IP addresses.
  • Users and enterprises are urged to reset credentials and inspect historical media for accidentally leaked access secrets.

Sources & References

โ† All News Tools