Gyazo, a cloud-based tool for capturing and sharing screenshots operated by Helpfeel, disclosed a data breach stemming from exploitation of a server vulnerability. The incident resulted in unauthorized access to approximately 23.62 million user records from the platform's database.

The service, which automatically uploads screen captures to the cloud and generates shareable links for distribution across messaging apps, forums and social networks, counts roughly 23 million users globally who have contributed 3.1 billion media items. The platform is particularly prevalent among gaming communities.

The breach occurred on September 11, 2026, when attackers gained database access. Gyazo's security team detected the unauthorized activity the following day and patched the vulnerability, but the data had already been compromised. The platform has since gone offline to perform maintenance and remediation work.

Currently, the Gyazo service is temporarily suspended for maintenance as a preventive measure. We sincerely apologize for any inconvenience caused. Please wait a little longer until recovery.

Gyazo, in a post on X

Gyazo's investigation confirmed that the third party accessed the database and obtained user information and metadata tied to uploaded images without authorization. The scope of exposed data varies by account and may encompass multiple categories of information.

Exposed data categories

  • Names and nicknames
  • Email addresses
  • Password hashes
  • User and device identifiers
  • Login session IDs
  • X integration tokens
  • Google SSO email addresses
  • Profile details
  • Subscription information
  • Billing status
  • Usage statistics

The breach also exposed 490 million image metadata records, predominantly from images uploaded before January 2019. These records contain image IDs used to construct URLs, upload source IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases protecting private images.

Helpfeel noted that image IDs could potentially enable access to corresponding image content, prompting the company to temporarily restrict access to files whose records were compromised. The attackers also obtained a list identifying private images, and Gyazo cannot exclude the possibility that some were accessed.

The investigation has not revealed evidence of data deletion resulting from the incident. Gyazo found no indication that its sister services under the Helpfeel and Cosense brands experienced data theft.

The company is reaching out to impacted users directly while collaborating with external security experts on its investigation. Authorities have been notified of the incident. Users are urged to change their Gyazo passwords immediately and update credentials on any other services where they reused the same password, while remaining vigilant for suspicious messages.