Abstract glass data vault fractured by a security breach
Data Breach Published 18 Sept 2026 3 min read2 sources

Gyazo Breach: Change Passwords and Review Old Captures

Gyazo's owner says a breach exposed user records and image metadata, including information used to build image links. The priority is not just a password change: review what sensitive material you have stored in captures, too.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Helpfeel reports roughly 23.62 million user records, not a confirmed count of individual people. Anonymous accounts are included.
  • Exposed image metadata includes image IDs, OCR text and location data where present. Helpfeel cannot rule out some private images having been viewed.
  • Change your Gyazo password and any reused or similar passwords elsewhere. Review sensitive captures; a VPN cannot retract information already stored with a service.

What Gyazo has confirmed

In a notice published on 16 September, Helpfeel said an attacker exploited a vulnerability in Gyazo's image upload server on 11 September and accessed its database. The company says it blocked the identified access routes and fixed the vulnerability on 12 September. Its investigation remains ongoing; these are the findings in that notice, not a final forensic account.

About 23.62 million user records were disclosed. Depending on the user, the fields include email addresses, password hashes, login session IDs and connected X integration tokens. That total includes anonymous accounts, and Helpfeel is still determining the number of people whose personal information was exposed. The company says no payment information, including credit card numbers, was disclosed.

Helpfeel says it has taken authentication-related measures including invalidation and restrictions. It does not specify every affected token or session in the notice, so readers should not infer that a password reset alone settles every possible account-access issue.

Why old screenshots deserve attention

The company reports approximately 490 million image-metadata records, primarily associated with images registered in or before January 2019. It also reports separately retrieved metadata for about 2.4 million images. These are records, not a confirmed count of pictures viewed by the attacker; the notice does not establish whether the two sets overlap.

The exposed fields include image IDs used to construct links, upload IP addresses, OCR text, source URLs and EXIF location data where present. Helpfeel says the link information could let a third party view corresponding images and has temporarily disabled viewing of some images. It also cannot rule out some private images having been viewed.

That makes this more than a contact-list breach. A capture can contain a document, address or account detail even when its filename looks harmless. The Hacker News notes that older captures on free accounts can remain accessible by URL despite no longer appearing among the captures the account can browse. A short visible history is not proof that older material was deleted.

What to do now

Open Gyazo through your usual bookmark or by typing its address, rather than following an unsolicited reset message. Helpfeel asks all Gyazo users to change their passwords, and to change the same or similar passwords used on other services. Use a distinct password for each account.

Review captures you can access for sensitive information. If a capture contains a still-valid password, API key or recovery code, replace or revoke that secret at the service that issued it. Removing a capture can reduce future availability but cannot erase a copy somebody may already have obtained. Ask Gyazo support about inaccessible older material rather than assuming it is safe.

For work documents or somebody else's personal information, notify the appropriate IT or privacy contact instead of sharing the image link more widely. Watch for incident-themed phishing. Helpfeel plans email notifications for identified affected users and web-interface notices for users it cannot reach by email.

Where VPN protection ends

A VPN can protect supported network traffic between your device and its server. It cannot patch Gyazo's infrastructure, remove stored OCR text or make an exposed image link secret again. Account hygiene and reviewing the content entrusted to the service are the relevant actions here.

Our earlier LeakyLinks explainer covers a different route to private-link exposure: submitting sensitive URLs to public scanners. Do not paste a Gyazo link containing private material into a public scanning service to check whether it is safe.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps