What happened
Short version: someone found a chink in a Gyazo server, and yes, they poked it. On September 11, 2026 attackers exploited a server vulnerability and managed to grab roughly 23.6 million users worth of records from Gyazo’s database. The company that runs Gyazo, Helpfeel, noticed suspicious activity the next day, patched the hole, and then took the service offline while they investigate and do damage control.
The platform — popular for quick screenshots and screen recordings, especially in gaming circles — temporarily suspended access to files whose records were exposed because the attackers also snagged image-related data that could be used to reconstruct links to content.
What was exposed and what it means
The types of information leaked vary by account, but the range is broad. If your account was in the haul, attackers may have seen one or more of the following:
- Names or nicknames
- Email addresses
- password hashes
- User and device IDs
- Login session IDs
- Integration tokens for social platforms
- Emails tied to Google SSO
- Profile details
- Subscription and billing status
- Usage statistics
Separately, the attackers obtained a huge amount of image metadata — most of it from uploads before January 2019 — roughly 490 million images worth of metadata. That includes things like image IDs (which can be used to form URLs), upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and even hashed passphrases for private images. The breach also included a list identifying which images were marked private, so the company can’t rule out that some private content might have been viewed.
Helpfeel says they didn’t find signs that data was deleted, and so far other related services don’t appear to be affected. They are notifying impacted users, working with outside forensic experts, and contacting authorities.
Quick practical notes: because image IDs can be used to reach content, Gyazo has temporarily disabled access to affected files while they clean up and investigate.
What you should do right now
- Change your Gyazo password immediately and don’t reuse it anywhere else.
- If you used the same password elsewhere, change those too — attackers love credential stuffing.
- Enable two-factor authentication where available.
- Keep an eye on your inbox and messages for phishing or suspicious password-reset attempts.
- Check your billing statements and subscription settings for odd activity.
- If you used social or SSO integrations, consider revoking and reissuing tokens where possible.
If you’re the kind of person who stores weirdly sensitive stuff in screenshots (we see you), assume anything exposed could have been looked at and act accordingly. The company promises to keep users updated as the probe continues — but in the meantime, hustle to secure your accounts and watch for scams.