Skip Navigation

September 21, 2026 |

Gyazo Breach Exposes User Data and Image Metadata Records

Loading table of contents...

At a glance:

  • A threat actor exploited a vulnerability in Gyazo's image upload server, gained unauthorized access to company systems, and accessed customer data on September 11, 2026.

  • The breach exposed approximately 23.62 million user records and approximately 490 million image metadata records, including image identifiers, login session IDs, integration tokens, OCR-extracted text, and information related to private images.

  • The most significant challenge for affected organizations is determining what information may have been stored within screenshots and whether historical image links contained business-sensitive content.

Threat summary

On September 16, 2026 Helpfeel (formerly Nota) disclosed a breach affecting Gyazo, its cloud-based screenshot and screen-recording sharing service. The company determined that an attacker exploited a vulnerability in Gyazo's image upload infrastructure on September 11 and used that access to reach the service's database.

Gyazo is commonly used to capture screenshots, GIFs, and short recordings and share them using generated links. In many organizations, screenshots created for support tickets, troubleshooting activities, documentation, collaboration, and project work accumulate over time and remain accessible through the platform.

The company confirmed that exploitation enabled arbitrary command execution on a Gyazo upload server and resulted in unauthorized access to stored data. The vulnerable access path was remediated on September 12. The disclosure does not identify the vulnerability type, affected software component beyond the upload server, authentication requirements, or exploitation method.

The attacker obtained approximately 23.62 million user records containing account-related information, including names, email addresses, password hashes, login session identifiers, device identifiers, profile information, and integration-related data. The attacker also accessed approximately 490 million image metadata records, primarily associated with images uploaded before January 2019. Exposed metadata included image identifiers, OCR-extracted text, source URLs, upload IP addresses, user-agent strings, image titles, EXIF location data where present, and hashed passphrases associated with private images. The attacker also obtained a list identifying private images.

The exposed metadata contains information used to construct Gyazo image URLs. As a result, the overall impact depends heavily on the contents of affected screenshots and how organizations used the platform. Helpfeel temporarily restricted access to some images as part of its response.

Analysis

The organizations most likely to be affected are those that routinely use screenshots as part of operational workflows. Support teams, IT administrators, developers, project teams, and customer-facing personnel often use screenshot-sharing platforms to communicate technical issues, document processes, or exchange information quickly.

This type of platform is attractive to attackers because it sits at the intersection of users and shared information. Unlike a traditional breach involving only account records, a screenshot-sharing service can contain years of accumulated business content. In this case, the exposed data included both account information and metadata associated with hundreds of millions of images.

The confirmed impact is limited to the disclosure of user records, image metadata, and information identifying private images. The available evidence does not establish how the stolen data has been used since the intrusion or whether affected images were subsequently viewed.

The operational impact is likely to vary significantly between organizations. For some, Gyazo may have been used only for routine screenshots with limited business value. For others, screenshots may have been embedded throughout support systems, internal documentation, project records, knowledge bases, and collaboration platforms. The exposure of image identifiers and OCR-extracted text may make those images easier to locate, classify, and review.

Mitigations

  • Organizations that use Gyazo can start by identifying where the platform is used and which users, teams, and business processes rely on it. This provides a clearer picture of what information may have been exposed and helps focus response efforts on the systems and users most likely to be affected.

  • Helpfeel has advised users to change their Gyazo passwords and any other accounts using the same or similar credentials. This reduces the value of exposed authentication data and helps limit opportunities for unauthorized account access.

  • Organizations may also benefit from reviewing how Gyazo was used to share information internally and externally. Screenshots embedded in support tickets, knowledge bases, project documentation, and collaboration platforms can help determine whether sensitive business information was present in affected content and whether additional remediation is required.

  • Accounts connected to Gyazo through identity providers or third-party services warrant additional review. Understanding which integrations were used helps security teams assess whether exposed account information creates additional risk for related services.

  • The disclosure of user information also creates opportunities for follow-on phishing activity. Monitoring for messages referencing Gyazo, shared screenshots, password resets, or account notifications can help identify attempts to leverage the incident for credential theft or social engineering.

  • Affected parties should track updates from Helpfeel's ongoing investigation as additional findings may refine the scope of affected data and influence response activities.


ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up