Gyazo, a cloud-based screenshot and screen-recording platform operated by Helpfeel, has confirmed a data breach in which attackers exploited a server vulnerability to steal roughly 23.62 million user records. The incident occurred on September 11, 2026, according to the company, and the platform has since been taken offline for maintenance as a preventive measure. Gyazo said it detected suspicious activity on September 12 and fixed the vulnerability the attackers used, but the data had already been taken by then. The company said it is notifying affected users directly.

The breach affected a service that automatically uploads user screen captures to the cloud and generates shareable links for chats, forums and social media. Gyazo is especially popular in gaming communities and claims 23 million users worldwide, who have submitted 3.1 billion media items. Helpfeel said its investigation confirmed that a third party accessed Gyazo's database and that user information and metadata tied to uploaded images were disclosed without authorization.

The exposed data varies by user, according to Gyazo, and may include one or more categories of records. The dataset includes anonymous account records, though the company did not say what percentage of the total those represent. Gyazo also said the incident exposed 490 million image metadata records, most associated with images uploaded before January 2019. That metadata includes image IDs used to build image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs and hashed passphrases for private images.

Helpfeel noted that image IDs could potentially be used to reach the corresponding content, which is why the company has temporarily disabled access to files whose records were exposed. The company also said the hackers obtained a list identifying private images and that it cannot rule out that some of those images were viewed. Gyazo said its investigation has found no signs that data was deleted as a result of the incident, and no evidence that its other Helpfeel and Cosense services had data stolen.

The company said it is working with external experts, has contacted authorities and is notifying affected users as the investigation continues. All Gyazo users are advised to change their passwords on the service and on any other platforms where they use the same credentials, and to remain alert for suspicious communications. The outage and credential exposure carry particular weight for Gyazo's US user base, which includes gamers and other users who routinely share links to captured images across public forums and social platforms.

More cybersecurity news from TechManNews.