Customer records exposed: 24 million (Source: Infosecurity Magazine, citing Gyazo disclosure (September 11, 2026))
What happened
A breach at Gyazo, a Japanese image-sharing and screenshot service, exposed nearly 24 million customer records after attackers exploited a vulnerability in an upload server, according to Infosecurity Magazine. The breach was disclosed on September 11, and Gyazo developer Helpfeel detailed the incident in a blog post on September 16.
The metadata went further than the accounts
Beyond the customer records, Helpfeel confirmed that 490 million metadata records tied to images were also exposed. That metadata included image IDs, source IP addresses, user agent strings, EXIF location data, OCR text extracted from images, titles, source URLs, and hashed passphrases. Helpfeel said the exposed metadata could let a third party construct image URLs and view images without authorization, and it temporarily disabled viewing of some images as a result.
Why this matters beyond consumer accounts
Michael Bell, founder and CEO at Suzu Labs, said Gyazo is used heavily by developers to share terminal output, API keys, credentials in config files, and internal application screenshots. The service's OCR feature, which makes captures searchable, extracted and stored that text alongside the images, turning what was once pixels into indexed, searchable data. Seemant Sehgal, CEO at BreachLock, said the metadata layer carries the broadest reach of the incident, arguing that EXIF coordinates, OCR-extracted text, and session and URL-construction data give an attacker material to reconstruct behavior and location history for people who uploaded a screenshot and did not expect it to resurface.
A mitigating factor: the age of the data
Damian Skeeles, senior solutions engineer manager at Filigran, offered a partial counterpoint: the exposed metadata is tied to images registered on or before January 2019. He said that age reduces the practical impact of any credentials captured in old screenshots, provided organizations cycle credentials on a regular schedule rather than treating a one-time rotation as sufficient.
Response and the broader lesson
Helpfeel said it has remediated the vulnerability used in the attack and is urging affected users to change passwords on Gyazo and any other service where credentials were reused, noting the stored passwords were hashed. CyberSmart CEO Jamie Akhtar said the incident reflects a broader operational pattern for internet-facing services: patch and test rigorously, restrict what upload systems can access, monitor continuously for suspicious behavior, and after a breach, invalidate sessions and tokens and force password resets. Comparitech's Paul Bischoff separately flagged that exposed email addresses and identifying information could be used to craft convincing phishing messages impersonating Gyazo or related companies.
What to ask your team
For a budget-holder, the relevant question is not whether Gyazo specifically is in use, but whether any screenshot, annotation, or OCR-enabled SaaS tool is embedded in developer workflows without a data-retention or credential-hygiene policy attached to it. Ask your team which cloud-based capture or annotation tools are approved for use, whether OCR-searchable text from screenshots is treated as sensitive data, and how quickly credentials exposed in shared images get rotated.





