Your Private Screenshots Were One Server Bug Away From Public View
A screenshot often looks disposable. In a support ticket, a developer chat or a hurried handover, it can contain passwords, customer names, internal dashboards, API tokens and whatever else happened to be visible for a few seconds. Gyazo’s breach shows what happens when years of that supposedly transient material sit behind one vulnerable upload service.
Helpfeel says an attacker exploited a flaw in Gyazo’s image-upload server on 11 September, obtained unauthorised access and executed arbitrary commands. The company detected suspicious activity that evening, blocked the identified routes by early 12 September and later confirmed that data had left its systems.
The breach was bigger than a user table
Helpfeel confirmed the unauthorised disclosure of approximately 23.62 million user-related records. The fields vary by account but can include names, email addresses, password hashes, device and session identifiers, profile information, subscription status and integration tokens. The company says payment-card data was not exposed.
The second dataset is the more unusual risk. Approximately 490 million metadata records, mainly for images registered in or before January 2019, were disclosed. Helpfeel says this represented about 14.4 per cent of all image-related data. Another 2.4 million metadata records were retrieved through separate filtering.
- Image identifiers used to construct URLs
- Source IP addresses and browser user-agent data
- EXIF location information where present
- OCR text extracted from screenshots
- Image titles and source URLs
- Hashed passphrases for private images
That combination can reveal more than a conventional account breach. OCR can turn pixels into searchable secrets. EXIF fields can identify a place. Source URLs and IP addresses can connect a capture to an organisation. An image identifier can matter if it helps reproduce the route to the underlying content.
Possible access is not proof that every image was opened
Helpfeel has not said that all 490 million images were downloaded or viewed. It says some metadata is used to construct image URLs and therefore it cannot rule out that private images were accessed. That distinction matters. The confirmed event is the theft of user information and image metadata; access to individual private images remains under investigation.
The service temporarily disabled delivery of some images while applying countermeasures. A later service update described continuing availability effects. Users should not interpret a restored image as evidence that it was or was not accessed during the incident.
Treat old screenshots as retained records
- Reset the account password. Change any reused password elsewhere and review active sessions and connected integrations.
- Search for exposed secrets. Review what was captured in older screenshots. Rotate credentials, tokens and recovery codes that may still be valid.
- Check location and customer data. Consider whether screenshots contained addresses, health data, financial details or other regulated information.
- Review enterprise use. Organisations should identify teams that used Gyazo for support, engineering or incident evidence and include anonymous uploads where records permit.
- Preserve the timeline. Keep Helpfeel notifications, relevant access logs and rotation records. Do not destroy evidence before deciding whether notification or incident-response duties apply.
The strategic lesson is uncomfortable: a screenshot platform is also a document repository, an identity store and sometimes a shadow secrets manager. Retention, access control and deletion rules should reflect what the images contain, not how casually they were created.
Sources
- Helpfeel, notice and apology regarding unauthorised access to Gyazo, published 16 September 2026. No publication time was provided.
- Helpfeel, service impact update, published 18 September 2026. No publication time was provided.
- Gyazo user notice, published 16 September 2026. No publication time was provided.


