In short: On September 11, 2026, attackers exploited a command-execution flaw in Gyazo's upload server, accessing 23.62 million user records and metadata from roughly 490 million screenshots — including OCR-extracted text and EXIF geolocation. Helpfeel patched the server and blocked the attack by September 12; the incident was publicly disclosed September 15–21. If you use Gyazo, rotate your password and revoke its OAuth tokens now.
What happened
Gyazo is a widely used screenshot, GIF, and screen-recording sharing service operated by Japan-based Helpfeel Inc. On the evening of September 11, 2026, Helpfeel detected suspicious activity on its systems. An attacker had found a vulnerability in the image upload server that allowed arbitrary command execution within Helpfeel's backend. By the early hours of September 12, the company had severed the attacker's access routes and patched the flaw. The incident was reported to Japan's Personal Information Protection Commission (PIPC) on September 15.
A detailed technical disclosure was published September 17–21 by BleepingComputer, The Hacker News, SecurityWeek, and other security outlets. Our security blog covers similar incidents regularly.
What was exposed
The breach compromised 23.62 million user account records, including names, email addresses, password hashes, user and device IDs, session tokens, X (Twitter) OAuth tokens, Google SSO emails, profile details, usage statistics, and subscription and billing information. Payment card data was not affected, according to the company.
Equally significant is the image-metadata half of the breach: roughly 490 million records tied to uploaded screenshots. These include image IDs, upload-time IP addresses, User-Agent strings, EXIF geolocation data, OCR-recognized text extracted from the screenshots themselves, and the original source URLs of the pages being captured.
Why the OCR angle is alarming
Most users treat Gyazo as a neutral clipboard in the cloud — a fast way to share a screenshot without thinking twice. The breach reveals something less comfortable: every screenshot you uploaded was silently read by OCR, and the resulting text was stored as a structured, searchable metadata field on Gyazo's servers. That metadata could contain fragments of private conversations, banking or business interfaces, URLs you were visiting, open document content, or anything else visible on screen at capture time.
It is a reminder that convenience tools are rarely as stateless as they appear. Services that look like simple file storage often capture and retain far more about your activity than users expect.
How attackers can use this data
Credential stuffing. Password hashes can be cracked offline, especially weak or widely reused passwords. If the same password was used for email, banking, or social accounts, attackers gain entry to all of them.
OAuth account takeover. Stolen X OAuth tokens and Google SSO credentials can enable access to those linked accounts. Helpfeel has invalidated tokens on its end, but manually revoking Gyazo access in X and Google settings remains the right step.
Targeted phishing. Email plus profile plus OCR screenshot content gives attackers enough personal context to craft highly convincing personalized phishing messages.
Location and device fingerprinting. Upload-time IP addresses combined with User-Agent strings can reconstruct roughly where you were and what device you used.
What to do right now
- Change your Gyazo password — even if your hash has not been cracked yet, rotating the credential removes the risk.
- Change the same password anywhere else you used it. Email, banking, and messaging accounts come first.
- Revoke Gyazo's OAuth access in X Settings → Security → Connected Apps, and in Google Account → Security → Third-party access.
- Enable two-factor authentication on critical accounts — a stolen password alone is then not enough to break in.
- Check your email at haveibeenpwned.com to see if it appeared in this or other breaches.
Using a password manager that generates a unique password for every service means one breach never cascades into another. LiMP VPN secures your network traffic in transit — password hygiene and access revocation are the layer that protects your accounts after a breach like this.
