All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Gyazo, a popular screen recording and screenshot tool, has suffered a data breach.
On September 11, hackers broke into Gyazo’s database and accessed 490 million image metadata records, including text pulled from screenshots, location data, email addresses, password hashes, login session IDs, and a list of images that users had marked as private.[1]
Think back to every screenshot you have shared with a quick Gyazo link: the bank balance you sent a friend, a private chat you wanted a second opinion on, or the code snippet with an API key you forgot to blur. All this information could allow attackers to run convincing phishing scams, steal your identity, or simply leak private information.
If you’re a Gyazo user, here’s everything you need to know about the Gyazo data breach and what you can do to minimize the misuse of your leaked data.
Privacy risks of the Gyazo data leak
What can you do to protect yourself
The bottom line
What did hackers steal from Gyazo
Gyazo’s breach has exposed 23.62 million user-related records and 490 million image metadata records. The parent company, Helpfeel, has not given out many technical details about how the breach occurred, but it said attackers exploited a vulnerability in its image upload server on September 11.
The company detected suspicious activity that evening, blocked the access routes by the early hours of September 12, and remediated the vulnerability. However, the data had already been stolen. Since then, Gyazo has been taken offline for maintenance, and the company has been working with external experts and authorities.
The exposed user data includes:
- Names or nicknames
- Email addresses
- Login session IDs
- Password hashes
- User and device IDs
- Google SSO email addresses
- Profile information
- Subscription information
- Billing status
- X integration tokens
- Usage statistics
Gyazo also confirmed that the breach exposed 490 million image metadata records, most of which were associated with images uploaded before January 2019. This could include:
- Image IDs, which can be used to construct image URLs
- Exchangeable Image File Format (EXIF) location data, if contained in the image
- Image titles and source URLs
- Hashed passphrases for private images
- Text extracted from the image by OCR
- The IP address and browser information of the person who uploaded them
The attackers also obtained a list identifying images that had been marked as private. Gyazo said it cannot rule out that some private images were viewed by the attackers, which is why it has temporarily disabled access to some affected images.
Privacy risks of the Gyazo data leak
The nature of the data leaked in this breach could tie a real person to their location, accounts, and screenshots, making them vulnerable to a variety of cybersecurity threats.
- Phishing and scams: This is the most immediate risk. Attackers now have millions of email addresses that can be linked to names, billing status, and subscriptions. They could target you with highly convincing fake emails posing as Gyazo security notices or asking you to reset your password. These messages could contain malicious links that install malware on your device or lead to fake login pages designed to steal your banking credentials. Since Gyazo is particularly popular in gaming communities, users should also be wary of scams on platforms such as Discord or Steam.
- Account takeover: Leaked password hashes are not plaintext passwords, but weak or commonly used passwords could potentially be cracked, depending on how Gyazo hashed them. This can lead to credential stuffing, especially if you used the same password on other sites and your password was included in the leak. Attackers can try to log into other accounts with your Gyazo password. Also, the leaked X integration tokens and login session IDs can provide access to linked accounts or hijack sessions if those credentials remained valid at the time of the leak.
- Exposure through screenshots: People have a habit of screenshotting all kinds of things, be it messages, documents, bank balances, passwords, email inboxes, and even medical information. Since the attackers obtained OCR-extracted text from the image metadata, they could potentially search the stolen data for things like account numbers and passwords. The image IDs could also potentially be used to construct image URLs and access corresponding content, which is why Gyazo has temporarily disabled access to some affected images.
- Location and de-anonymization: EXIF location data may reveal where a photo was taken. Combined with IP addresses and other account information, attackers could get a better idea of who you are, even if you have been using a pseudonym for your Gyazo account. This could increase the risk of stalking, harassment, and doxing, particularly in gaming communities.
- Identity theft: Although personal details such as credit card and Social Security numbers were not leaked in this breach, attackers could potentially combine the exposed information with data from other breaches to build a more complete profile of a victim. This could increase the risk of identity theft and other forms of fraud.
What can you do to protect yourself
Gyazo said: “We are preparing notifications for Gyazo users. We will determine which users to contact based on the progress of our investigation and will notify them on a rolling basis.”
In the meantime, there are several steps you can take to protect yourself:
- Change your passwords: Once Gyazo is back online, change your current password and choose something strong and unique. Most importantly, if you have reused your Gyazo password for other accounts, change those passwords immediately too. You can use a reliable password manager that can not only suggest strong passwords but also store them securely for you.
- Revoke Gyazo’s access to your X account: If you have linked your X account with Gyazo, you should invalidate the integration token. You can also log out of all Gyazo sessions to invalidate session ID tokens.
- Do not click on any suspicious links: Be wary of any phishing emails or SMS messages you receive claiming to be from Gyazo support. Don’t click on any links within these messages. If you’re suspicious about their legitimacy, contact Gyazo through its official channels and confirm whether the message is genuine.
- Turn on two-factor authentication: Do this for every account that offers it, especially your email account, since it adds an extra layer of protection. You can also check whether your email has appeared in a data breach by using a service such as Have I Been Pwned.
- Use an identity theft protection service: A service like this can scan leaked databases and the dark web for your personally identifiable information. It can then alert you if it finds your information and, depending on the service, may offer identity restoration assistance.
The bottom line
If you are or have been a Gyazo user, your private screenshots could potentially be compromised. Although Gyazo hasn’t provided much technical detail about how the attack actually happened, names, email addresses, password hashes, X integration tokens, EXIF location data, IP addresses, and device IDs are all among the exposed information.
While you wait for Gyazo’s next steps, you can still take several steps to reduce the chances of your information being misused. Change your passwords, especially if you have reused them across various accounts, enable 2FA, revoke Gyazo’s access to your X account, and never click on suspicious links you receive in messages claiming to be from Gyazo. Lastly, consider getting an identity theft protection tool, which could help you locate your leaked personal information.
[1] Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo