Gyazo data breach leaves over 23 million user records exposed, includes half a billion metadata points
Leaked data could be used to access and view images that users shared.

Image by Cybernews.
- Gyazo says attackers exposed 23.62 million user records and about 490 million image metadata records.
- The exposed data includes names, emails, password hashes, device IDs, login sessions, and some connected account tokens.
- Some metadata could help attackers access private images, so Gyazo temporarily disabled viewing of certain images.
- Gyazo will require password changes and advises users to update reused passwords on other accounts.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Helpfeel’s image-sharing service Gyazo has confirmed that a recent data breach exposed millions of records. The service, popular among gamers and streamers, said the attack happened on September 11th.
Attackers exploited a bug in Gyazo’s image upload server, gaining access that allowed cybercrooks to execute arbitrary commands, Gyazo explained in a data breach notice. According to the company, attackers accessed over 23 million user records and a staggering 490 million image metadata records.
Gyazo is a massively popular service with over 3 billion uploads. The service allows users to make and instantly share screensnaps, record quick clips, and share them via a cloud service. The Kyoto-based service owes its early growth to heavy use by communities of popular games such as Minecraft.
What details did the Gyazo data breach expose?
According to the company, intruders accessed its systems on September 11th, and it detected “suspicious activity” the same evening. Gyazo claims that the intrusion was stopped by the early hours of the next day.
Our subsequent investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata associated with uploaded images had been disclosed without authorization,Gyazo’s owner Helpfeel explained.
However, the short time attackers spent in Gyazo’s systems was enough to access massive amounts of personal information. According to the service, 23.62 million user records were exposed. While user records and user count are not the same, the service has around 23 million users.
We have reached out to the company to clarify whether all of its users were exposed in the data breach.
According to the company, the leaked user details include:
- Name (any text entered by the user, such as a name or nickname)
- Email address
- Password hash
- User ID
- Device ID
- Login session ID
- X (formerly Twitter) integration token (if connected)
- Email address associated with Google SSO (if connected)
- Profile information
- Language preference
- Registration date and time
- Last login date and time
- Subscription plan
- Billing status (does not include credit card numbers or other payment method information)
- Usage statistics
“The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar information. We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization,” Helpfeel said.
While the company explained that it’s still investigating the potential extent of possible harm, attackers could exploit stolen details to impersonate users or attempt account takeover. Depending on how strong the password encryption was, login credentials may also have been impacted.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
To make matters worse, attackers also managed to access a treasure trove of image metadata. Moreover, Helpful specified that by “images” it means “all content captured and stored via Gyazo, including screenshots, GIFs, and videos.”
So far, the company confirmed that attackers accessed around 490 million metadata records. The only silver lining is that the leaked metadata records mostly come from content uploaded prior to January 2019.
Additionally, metadata for over 2 million images was retrieved separately using specific filtering criteria and disclosed without authorization.
The affected metadata includes information used to construct Gyazo image URLs. This information could be used by a third party to access and view the corresponding images without authorization. We have temporarily disabled viewing of some images to prevent further harm,Helpfeel explained.
The company admitted that the initial investigation points to attackers obtaining a list that allows them to identify private images. That means that some private images may have been viewed by attackers.
The metadata involved in the breach includes:
- Image ID (information used to construct the image URL)
- Source IP address used for the upload
- User-Agent
- EXIF location data (if contained in the image)
- OCR text extracted from the image
- Image title
- Source URL and other metadata
- Hashed passphrase for private images
- Other related information
Gyazo’s next steps
The company said it plans to reach out to all exposed users who had a registered email address. At the moment, the company is still trying to identify who was exposed in the attack, as exposed user records vary across users.
“For users we are unable to reach by email, such as those with anonymous accounts without a registered email address or similar contact information, we plan to provide notifications through the Gyazo web interface,” the company explained.
The company will require all users to change their passwords to avoid unwanted attention to their accounts. Helpfeel also advised users who reuse passwords to change them on accounts that use the same password as Gyazo.
The company’s other products, such as Helpfeel and Cosense, don’t share the same system as Gyazo and were not impacted by the recent data breach. However, some Gyazo images may not load, as they’ve been made unavailable.