Skip to main content
The Wire
CyberNews by Zentrya One
critical Data Breaches

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Entries

Gyazo disclosed a major breach exposing 23.62 million user records and metadata for roughly 490 million images, potentially enabling unauthorized access to some uploaded content.

Image-sharing platform Gyazo has disclosed a major data breach exposing approximately 23.62 million user records and metadata associated with roughly 490 million uploaded images.

Gyazo operator Helpfeel said an attacker exploited a vulnerability in the service's image upload server, allowing them to execute arbitrary commands and gain unauthorized access to Gyazo's database. The company detected suspicious activity on September 11, 2026, and says it blocked the identified access paths and fixed the exploited vulnerability by early September 12.

What Data Was Exposed?

The information varies between users, but potentially exposed account data includes:

  • Names or nicknames
  • Email addresses
  • Password hashes
  • User and device IDs
  • Login session IDs
  • Profile information
  • X integration tokens for connected accounts
  • Google SSO email addresses
  • Registration and recent login information
  • Subscription plans and billing status

Helpfeel says credit card numbers and other payment information were not exposed. The 23.62 million figure represents records rather than a confirmed number of individual people and includes anonymous accounts without registered email addresses.

490 Million Image Metadata Records Accessed

The breach also exposed metadata for approximately 490 million images, primarily associated with content registered before January 2019. Another roughly 2.4 million metadata records were obtained under separately narrowed conditions.

Potentially exposed metadata includes:

Data Potential Risk
Image IDs Could help reconstruct Gyazo image URLs
Source IP addresses Network/location-related information
EXIF location Possible geographic information
OCR text Text extracted from screenshots/images
Image titles Context about captured content
Source URLs Websites associated with captures
User-Agent Device/browser information
Private-image passphrase hashes Authentication-related exposure

This part of the breach is particularly important because Gyazo confirmed that the exposed metadata contains information used to construct its image URLs.

Private Images May Have Been Viewed

Gyazo normally allows captures to be accessed through their unique URLs. Helpfeel says the stolen metadata could potentially allow a third party to construct URLs and access corresponding images without authorization.

The attacker also obtained a list identifying private image files.

Helpfeel said it cannot completely rule out the possibility that some private images were viewed by the attacker. As a precaution, the company has temporarily disabled access to some affected images.

Importantly, Helpfeel has confirmed exposure of image metadata, not a bulk theft of all 490 million underlying image files. However, because image IDs can be used to construct links, the metadata itself creates a potential path to unauthorized image access.

How the Attack Happened

The currently known attack chain is straightforward:

Vulnerability in Gyazo image upload server

→ Attacker executes arbitrary commands

→ Unauthorized access to internal systems

→ Gyazo database accessed

→ 23.62 million user records exposed

→ ~490 million image metadata records exposed

Helpfeel has not publicly disclosed the specific vulnerability or technical exploitation method used against the upload server.

What Gyazo Users Should Do

Helpfeel is advising all Gyazo users to change their passwords, even if they have not yet received an individual notification.

Users should also:

  • Change passwords on other services if the same or a similar password was reused.
  • Be cautious of phishing emails referencing the Gyazo breach.
  • Avoid clicking unexpected password-reset or account-verification links.
  • Review connected X accounts where applicable.
  • Monitor accounts for suspicious login activity.
  • Treat sensitive information contained in older Gyazo captures as potentially at risk if notified that related records were affected.

Helpfeel says it has already invalidated or restricted affected authentication-related information where appropriate.

The company plans to contact potentially affected users through their registered email addresses, while users without an email address may receive notifications through the Gyazo interface.

Security Takeaway

The Gyazo incident demonstrates why metadata can be almost as sensitive as the underlying content.

In this case, the exposed records did not merely describe uploaded images. Some contained identifiers capable of constructing image URLs, along with IP addresses, OCR text, source URLs and potentially EXIF location information.

The breach can therefore be summarized as:

Upload Server Vulnerability → Command Execution → Database Access → User Data Exposure + Image Metadata Exposure → Potential Unauthorized Image Access

Gyazo says the intrusion path has been blocked and the vulnerability fixed, but its investigation into the full scope and potential secondary harm remains ongoing.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.