Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Entries
Gyazo disclosed a major breach exposing 23.62 million user records and metadata for roughly 490 million images, potentially enabling unauthorized access to some uploaded content.

Image-sharing platform Gyazo has disclosed a major data breach exposing approximately 23.62 million user records and metadata associated with roughly 490 million uploaded images.
Gyazo operator Helpfeel said an attacker exploited a vulnerability in the service's image upload server, allowing them to execute arbitrary commands and gain unauthorized access to Gyazo's database. The company detected suspicious activity on September 11, 2026, and says it blocked the identified access paths and fixed the exploited vulnerability by early September 12.
What Data Was Exposed?
The information varies between users, but potentially exposed account data includes:
- Names or nicknames
- Email addresses
- Password hashes
- User and device IDs
- Login session IDs
- Profile information
- X integration tokens for connected accounts
- Google SSO email addresses
- Registration and recent login information
- Subscription plans and billing status
Helpfeel says credit card numbers and other payment information were not exposed. The 23.62 million figure represents records rather than a confirmed number of individual people and includes anonymous accounts without registered email addresses.
490 Million Image Metadata Records Accessed
The breach also exposed metadata for approximately 490 million images, primarily associated with content registered before January 2019. Another roughly 2.4 million metadata records were obtained under separately narrowed conditions.
Potentially exposed metadata includes:
| Data | Potential Risk |
|---|---|
| Image IDs | Could help reconstruct Gyazo image URLs |
| Source IP addresses | Network/location-related information |
| EXIF location | Possible geographic information |
| OCR text | Text extracted from screenshots/images |
| Image titles | Context about captured content |
| Source URLs | Websites associated with captures |
| User-Agent | Device/browser information |
| Private-image passphrase hashes | Authentication-related exposure |
This part of the breach is particularly important because Gyazo confirmed that the exposed metadata contains information used to construct its image URLs.
Private Images May Have Been Viewed
Gyazo normally allows captures to be accessed through their unique URLs. Helpfeel says the stolen metadata could potentially allow a third party to construct URLs and access corresponding images without authorization.
The attacker also obtained a list identifying private image files.
Helpfeel said it cannot completely rule out the possibility that some private images were viewed by the attacker. As a precaution, the company has temporarily disabled access to some affected images.
Importantly, Helpfeel has confirmed exposure of image metadata, not a bulk theft of all 490 million underlying image files. However, because image IDs can be used to construct links, the metadata itself creates a potential path to unauthorized image access.
How the Attack Happened
The currently known attack chain is straightforward:
Vulnerability in Gyazo image upload server
→ Attacker executes arbitrary commands
→ Unauthorized access to internal systems
→ Gyazo database accessed
→ 23.62 million user records exposed
→ ~490 million image metadata records exposed
Helpfeel has not publicly disclosed the specific vulnerability or technical exploitation method used against the upload server.
What Gyazo Users Should Do
Helpfeel is advising all Gyazo users to change their passwords, even if they have not yet received an individual notification.
Users should also:
- Change passwords on other services if the same or a similar password was reused.
- Be cautious of phishing emails referencing the Gyazo breach.
- Avoid clicking unexpected password-reset or account-verification links.
- Review connected X accounts where applicable.
- Monitor accounts for suspicious login activity.
- Treat sensitive information contained in older Gyazo captures as potentially at risk if notified that related records were affected.
Helpfeel says it has already invalidated or restricted affected authentication-related information where appropriate.
The company plans to contact potentially affected users through their registered email addresses, while users without an email address may receive notifications through the Gyazo interface.
Security Takeaway
The Gyazo incident demonstrates why metadata can be almost as sensitive as the underlying content.
In this case, the exposed records did not merely describe uploaded images. Some contained identifiers capable of constructing image URLs, along with IP addresses, OCR text, source URLs and potentially EXIF location information.
The breach can therefore be summarized as:
Upload Server Vulnerability → Command Execution → Database Access → User Data Exposure + Image Metadata Exposure → Potential Unauthorized Image Access
Gyazo says the intrusion path has been blocked and the vulnerability fixed, but its investigation into the full scope and potential secondary harm remains ongoing.
Related reporting
Rs. 2.87 Million Vanishes in 14 Minutes: Sri Lanka Banking Incident Raises Digital Fraud Questions
A Bank of Ceylon customer disputes 30 transactions totaling Rs. 2.869 million completed within 14 minutes. BOC says its systems were not breached, raising questions about credential theft, OTP security and digital banking fraud.
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claims it breached FBI systems and stole sensitive data on agents, employees and job applicants, while the FBI investigates unauthorized activity affecting FBIJobs.gov.
Revolut Data Breach Exposes Passports and Full Transaction Histories After Fake Government Request
Fintech giant Revolut has confirmed a data-security incident in which an unauthorized party obtained sensitive customer information after submitting fraudulent requests that appeared to come from a legitimate government agency.


