Gyazo breach exposes 23.62 million user records and image metadata
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 28th, 2026.
Users face a significant privacy and trust impact after attackers stole approximately 23.62 million Gyazo records. The incident involved a weakness in the screenshot-sharing platform’s image upload server. The stolen material included user records and metadata connected to hundreds of millions of images. The supplied evidence doesn’t specify that the image contents themselves were taken.
Metadata at this scale can still support profiling, phishing, and account targeting, depending on which fields were exposed. Organizations whose staff use screenshot-sharing services may also have business context connected to those accounts.
For leaders, the key point is that consumer tools used at work can become an unmanaged data channel. For defenders, identify enterprise use of Gyazo and prepare users for targeted messages or account-recovery attempts. Collaboration tools offer convenience, but they can also quietly expand an organization’s external data footprint. Identify workforce use of Gyazo and warn affected users to expect targeted phishing and recovery attempts.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.