Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

A massive data breach has struck Gyazo, a popular screenshot-sharing platform used by millions worldwide. The incident has exposed an astonishing 23.62 million user records and a further 490 million image metadata records, leaving users vulnerable to identity exposure and potential active attacks.

The compromised data includes sensitive information such as email addresses, usernames, passwords (hashed but not encrypted), and other personally identifiable details. Gyazo’s platform allows users to upload screenshots, which can be annotated with metadata like location tags, comments, and timestamps. This metadata has also been exposed in the breach, potentially revealing users’ online activities and behavior.

Gyazo is a cloud-based service that relies on user-generated content, making it susceptible to data breaches when vulnerabilities are exploited. The platform’s architecture likely plays a significant role in this incident: Gyazo uses AWS (Amazon Web Services) for hosting its servers, which can create security risks if not properly configured or maintained.

The impact of the breach is far-reaching and affects millions of users worldwide. Identity exposure can unlock active attack paths, allowing malicious actors to pivot from one user account to another within Gyazo’s platform. This cross-domain privilege escalation enables attackers to exploit vulnerabilities in other services connected to Gyazo, potentially leading to a broader cyberattack.

The exposed metadata records may also be used for targeted phishing attacks or social engineering campaigns. Users whose data has been compromised should remain vigilant and change their passwords immediately. To mitigate the risk of identity exposure, Gyazo users must also review their online activities and ensure they have not inadvertently shared sensitive information through the platform.

While Gyazo’s breach serves as a wake-up call for all users to take cybersecurity seriously, it is particularly crucial for individuals who share sensitive or confidential content on public platforms like Gyazo. To stay safe, users should always be cautious when uploading screenshots that contain personal data and ensure they are aware of their digital footprint.


Source: The Hacker News — 2026-09-17