Gyazo breach exposes 23.62 million users and image metadata

Gyazo breach exposes 23.62 million users and image metadata. Millions of Gyazo users now face account and privacy risk after attackers accessed the screenshot-sharing service’s database.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 21st, 2026.

Millions of Gyazo users now face account and privacy risk after attackers accessed the screenshot-sharing service’s database. Helpfeel says the attackers exploited a weakness in an image upload server on September 11th, ran arbitrary commands, and stole approximately 23.62 million user records. The exposed information included names, email addresses, password hashes, session IDs, device IDs, and tokens for connected accounts. Payment card data was not exposed. The incident also involved roughly 490 million image-metadata records, and the company says it cannot rule out access to some private images. That metadata included upload I P addresses, location data, extracted text, source URLs, and hashed passphrases. This creates risks ranging from credential reuse and session abuse to targeted phishing and exposure of sensitive screenshot content. Leaders should treat screenshot services as repositories of business context, not lightweight utilities. Defenders should identify corporate Gyazo use and watch for related account abuse. Affected users should reset Gyazo and reused passwords, then revoke active sessions and integration tokens.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Gyazo breach exposes 23.62 million users and image metadata
Broadcast by