Skip to content
Tech News
← Back to articles

Gyazo server flaw exploited to steal 23.6 million user records

read original get YubiKey 5 Series Security Key → more articles
Why This Matters

A major breach at the widely used Gyazo screenshot-sharing service exposed 23.6 million user records and nearly half a billion image metadata entries, highlighting the risks of centralized cloud services that store vast amounts of personal data. Because Gyazo integrates with social platforms like X and Google, the leaked credentials and tokens could enable follow-on attacks like account takeovers well beyond the platform itself.

Key Takeaways
Worth a Look

YubiKey 5 Series Security Key — With breaches like the Gyazo hack exposing millions of user records, strengthening your own account security is more important than ever. A YubiKey adds hardware-based two-factor authentication that makes it much harder for stolen credentials to be used against you. It's a simple, reusable way to lock down accounts on services that support it.

See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.

Gyazo is a cloud-based screenshot and screen-recording tool operated by Helpfeel that automatically uploads user screen captures to the cloud and gives them a shareable link to share on chats, forums, social media, etc.

It's especially popular in gaming communities and claims 23 million users worldwide, who have submitted 3.1 billion media items.

According to an announcement by the company, the incident occurred on September 11, 2026, allowing attackers to access its database and obtain approximately 23.62 million user records.

The company has now taken the platform offline while it conducts maintenance.

"Currently, the Gyazo service is temporarily suspended for maintenance as a preventive measure. We sincerely apologize for any inconvenience caused. Please wait a little longer until recovery," reads a post on X.

The company detected the suspicious activity on September 12 and fixed a vulnerability the attackers used to breach the platform, but by then, the data had already been stolen.

"Our subsequent investigation confirmed that the third party had accessed Gyazo's database and that user information and metadata associated with uploaded images had been disclosed without authorization," confirmed Gyazo in a statement published earlier this week.

Based on Gyazo's investigation, the data that has been exposed varies per user and may include one or more of the following:

Names/nicknames

... continue reading