← Back to news
BleepingComputer18 Sept 2026 · 2 min read

Gyazo says server vulnerability exposed data tied to 23.6 million accounts

Image-sharing platform Gyazo says a server vulnerability was exploited in an incident that exposed information associated with approximately 23.62 million user records. The company detected suspicious...

Image-sharing platform Gyazo says a server vulnerability was exploited in an incident that exposed information associated with approximately 23.62 million user records. The company detected suspicious activity on September 12, one day after the reported intrusion, and has temporarily suspended the service while it investigates and performs maintenance.

Gyazo, operated by Helpfeel, lets users upload screenshots and screen recordings to generate shareable links. The company says it has more than 23 million users and hosts billions of media items.

Information potentially exposed

According to Gyazo, the data involved differs by user. Exposed account information may include names or aliases, email addresses, password hashes, account and device identifiers, login session identifiers, profile data, subscription and billing-status details, usage data, Google single sign-on email addresses, and tokens connected to X integrations.

The company also reported that roughly 490 million image metadata records may have been accessed. Most of those records reportedly relate to images uploaded before January 2019. The metadata can include image identifiers, upload IP addresses, browser user-agent information, image titles, source URLs, OCR-derived text, EXIF location details, and hashed passphrases for private images.

Potential impact and response

Gyazo warned that image IDs could potentially be used to reach associated content. As a precaution, it has disabled access to files connected with exposed records. Attackers also obtained a list identifying private images, and the company said it cannot exclude the possibility that some private content was viewed.

The company said it has fixed the vulnerability used in the breach and has found no indication that data was deleted. It also said its investigation has not identified evidence that other Helpfeel or Cosense services were affected. Gyazo is working with external specialists, has contacted relevant authorities, and is notifying impacted users directly.

  • Gyazo users should reset their service password.
  • Anyone who reused that password elsewhere should change it on those services as well.
  • Users should watch for phishing emails or other suspicious messages that could use exposed personal details.
Share this article:TwitterLinkedIn