Your Private Screenshots Might Be Part of a 23.6M-Record Breach

A massive Gyazo breach has exposed sensitive personal details, including password hashes, location data, login details, and metadata linked to millions of images.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Gyazo, a popular screen recording and screenshot tool, has suffered a data breach.

On September 11, hackers broke into Gyazo’s database and accessed 490 million image metadata records, including text pulled from screenshots, location data, email addresses, password hashes, login session IDs, and a list of images that users had marked as private.[1]

Think back to every screenshot you have shared with a quick Gyazo link: the bank balance you sent a friend, a private chat you wanted a second opinion on, or the code snippet with an API key you forgot to blur. All this information could allow attackers to run convincing phishing scams, steal your identity, or simply leak private information.

If you’re a Gyazo user, here’s everything you need to know about the Gyazo data breach and what you can do to minimize the misuse of your leaked data.

In this article
What did hackers steal from Gyazo
Privacy risks of the Gyazo data leak
What can you do to protect yourself
The bottom line

What did hackers steal from Gyazo

Gyazo’s breach has exposed 23.62 million user-related records and 490 million image metadata records. The parent company, Helpfeel, has not given out many technical details about how the breach occurred, but it said attackers exploited a vulnerability in its image upload server on September 11.

The company detected suspicious activity that evening, blocked the access routes by the early hours of September 12, and remediated the vulnerability. However, the data had already been stolen. Since then, Gyazo has been taken offline for maintenance, and the company has been working with external experts and authorities.

The exposed user data includes:

  • Names or nicknames
  • Email addresses
  • Login session IDs
  • Password hashes
  • User and device IDs
  • Google SSO email addresses
  • Profile information
  • Subscription information
  • Billing status
  • X integration tokens
  • Usage statistics

Gyazo also confirmed that the breach exposed 490 million image metadata records, most of which were associated with images uploaded before January 2019. This could include:

  • Image IDs, which can be used to construct image URLs
  • Exchangeable Image File Format (EXIF) location data, if contained in the image
  • Image titles and source URLs
  • Hashed passphrases for private images
  • Text extracted from the image by OCR
  • The IP address and browser information of the person who uploaded them

The attackers also obtained a list identifying images that had been marked as private. Gyazo said it cannot rule out that some private images were viewed by the attackers, which is why it has temporarily disabled access to some affected images.

Privacy risks of the Gyazo data leak

The nature of the data leaked in this breach could tie a real person to their location, accounts, and screenshots, making them vulnerable to a variety of cybersecurity threats.

  1. Phishing and scams: This is the most immediate risk. Attackers now have millions of email addresses that can be linked to names, billing status, and subscriptions. They could target you with highly convincing fake emails posing as Gyazo security notices or asking you to reset your password. These messages could contain malicious links that install malware on your device or lead to fake login pages designed to steal your banking credentials. Since Gyazo is particularly popular in gaming communities, users should also be wary of scams on platforms such as Discord or Steam.
  2. Account takeover: Leaked password hashes are not plaintext passwords, but weak or commonly used passwords could potentially be cracked, depending on how Gyazo hashed them. This can lead to credential stuffing, especially if you used the same password on other sites and your password was included in the leak. Attackers can try to log into other accounts with your Gyazo password. Also, the leaked X integration tokens and login session IDs can provide access to linked accounts or hijack sessions if those credentials remained valid at the time of the leak.
  3. Exposure through screenshots: People have a habit of screenshotting all kinds of things, be it messages, documents, bank balances, passwords, email inboxes, and even medical information. Since the attackers obtained OCR-extracted text from the image metadata, they could potentially search the stolen data for things like account numbers and passwords. The image IDs could also potentially be used to construct image URLs and access corresponding content, which is why Gyazo has temporarily disabled access to some affected images.
  4. Location and de-anonymization: EXIF location data may reveal where a photo was taken. Combined with IP addresses and other account information, attackers could get a better idea of who you are, even if you have been using a pseudonym for your Gyazo account. This could increase the risk of stalking, harassment, and doxing, particularly in gaming communities.
  5. Identity theft: Although personal details such as credit card and Social Security numbers were not leaked in this breach, attackers could potentially combine the exposed information with data from other breaches to build a more complete profile of a victim. This could increase the risk of identity theft and other forms of fraud.

What can you do to protect yourself

Gyazo said: “We are preparing notifications for Gyazo users. We will determine which users to contact based on the progress of our investigation and will notify them on a rolling basis.”

In the meantime, there are several steps you can take to protect yourself:

  1. Change your passwords: Once Gyazo is back online, change your current password and choose something strong and unique. Most importantly, if you have reused your Gyazo password for other accounts, change those passwords immediately too. You can use a reliable password manager that can not only suggest strong passwords but also store them securely for you.
  2. Revoke Gyazo’s access to your X account: If you have linked your X account with Gyazo, you should invalidate the integration token. You can also log out of all Gyazo sessions to invalidate session ID tokens.
  3. Do not click on any suspicious links: Be wary of any phishing emails or SMS messages you receive claiming to be from Gyazo support. Don’t click on any links within these messages. If you’re suspicious about their legitimacy, contact Gyazo through its official channels and confirm whether the message is genuine.
  4. Turn on two-factor authentication: Do this for every account that offers it, especially your email account, since it adds an extra layer of protection. You can also check whether your email has appeared in a data breach by using a service such as Have I Been Pwned.
  5. Use an identity theft protection service: A service like this can scan leaked databases and the dark web for your personally identifiable information. It can then alert you if it finds your information and, depending on the service, may offer identity restoration assistance.

The bottom line

If you are or have been a Gyazo user, your private screenshots could potentially be compromised. Although Gyazo hasn’t provided much technical detail about how the attack actually happened, names, email addresses, password hashes, X integration tokens, EXIF location data, IP addresses, and device IDs are all among the exposed information.

While you wait for Gyazo’s next steps, you can still take several steps to reduce the chances of your information being misused. Change your passwords, especially if you have reused them across various accounts, enable 2FA, revoke Gyazo’s access to your X account, and never click on suspicious links you receive in messages claiming to be from Gyazo. Lastly, consider getting an identity theft protection tool, which could help you locate your leaked personal information.

4.8
Editorial Rating
Claim Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Notice and Apology Regarding a Data Breach Resulting from Unauthorized Access to Gyazo