Gyazo server flaw exploited to steal 23.6 million user records

A Devastating Data Breach Hits Gyazo, Exposing 23.6 Million User Records

Gyazo, a popular cloud-based screenshot and screen-recording tool used by millions of gamers worldwide, has fallen victim to a massive data breach. Hackers exploited a server vulnerability on September 11, 2026, stealing an astonishing 23.62 million user records from the platform’s database. The incident has left users concerned about their sensitive information, including passwords, email addresses, and personal details.

Gyazo’s cloud-based service allows users to upload screenshots and screen recordings directly to the platform, generating a shareable link for easy sharing on social media, forums, or chat platforms. With over 23 million registered users worldwide and 3.1 billion media items uploaded, Gyazo’s user base is substantial. The company has now taken the platform offline as a precautionary measure while it conducts maintenance to rectify the vulnerability.

The hackers gained unauthorized access to Gyazo’s database on September 11, with the breach only detected two days later, on September 12. By then, the data had already been stolen, leaving users vulnerable to potential identity theft and other malicious activities. According to an investigation by Gyazo, the exposed dataset includes a range of sensitive information for each user, including names/nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, usage statistics, and more.

What’s particularly concerning is that the hackers also obtained a list of private image IDs, which could potentially be used to access the corresponding content. Helpfeel, Gyazo’s parent company, has temporarily disabled access to files whose records were exposed as a precautionary measure. The firm also cannot rule out the possibility that some private images may have been viewed by the attackers.

While Helpfeel assures users that their other services, including Cosense and Helpfeel, had no data stolen in this incident, all Gyazo users are advised to change their passwords on the service and other platforms where they use the same credentials. Users should also remain vigilant for suspicious communications and be cautious when sharing sensitive information online.

This latest data breach serves as a stark reminder of the importance of robust cybersecurity measures in today’s digital landscape. As we continue to rely increasingly on cloud-based services, it’s crucial that companies prioritize their users’ security and take proactive steps to prevent such incidents from occurring in the first place.


Source: Bleeping Computer — 2026-09-18