ADVERTISEMENT

Gyazo data breach leaves over 23 million user records exposed, includes half a billion metadata points

Leaked data could be used to access and view images that users shared.

Gyazo logo visible on a laptop screen, via open tab, on the company's website.

Image by Cybernews.

Vilius Petkauskas
Vilius Petkauskas Deputy Editor
September 17, 2026 Updated: 5 minutes ago 3 min read
Key takeaways:

What details did the Gyazo data breach expose?

Our subsequent investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata associated with uploaded images had been disclosed without authorization,
Gyazo’s owner Helpfeel explained.
  • Name (any text entered by the user, such as a name or nickname)
  • Email address
  • Password hash
  • User ID
  • Device ID
  • Login session ID
  • X (formerly Twitter) integration token (if connected)
  • Email address associated with Google SSO (if connected)
  • Profile information
  • Language preference
  • Registration date and time
  • Last login date and time
  • Subscription plan
  • Billing status (does not include credit card numbers or other payment method information)
  • Usage statistics
ADVERTISEMENT
The affected metadata includes information used to construct Gyazo image URLs. This information could be used by a third party to access and view the corresponding images without authorization. We have temporarily disabled viewing of some images to prevent further harm,
Helpfeel explained.
  • Image ID (information used to construct the image URL)
  • Source IP address used for the upload
  • User-Agent
  • EXIF location data (if contained in the image)
  • OCR text extracted from the image
  • Image title
  • Source URL and other metadata
  • Hashed passphrase for private images
  • Other related information

Gyazo’s next steps

Vilius Petkauskas
Deputy Editor
ADVERTISEMENT