A student in Ohio has used Gyazo since school: one keystroke, a screenshot, a link to paste into Discord. She made the account in 2019 with the password she used everywhere then. This week that email address and a hash of that password are in a folder someone pulled out of Gyazo’s database, next to the IP address and the recognised text of every screenshot she ever took. She has not opened Gyazo in a year, and it does not matter.
Confirmation: confirmed by the company. Helpfeel, which runs Gyazo, published its notice on 16 September 2026 and set out the record counts and the fields itself.
What happened
On 11 September 2026 an attacker used a vulnerability in Gyazo’s image-upload server to run commands on it and reach the user database; Helpfeel found the intrusion the next day, cut the access off, and disclosed it on 16 September. That is the timeline in Helpfeel’s own notice, picked up by BleepingComputer and SecurityWeek on 18 September.
Gyazo is a screenshot and screen-recording tool: press a key, the capture goes to the cloud, you get a link. It has about 23 million users and holds more than three billion images, and it is a fixture in gaming, study and support chats because the link is faster than the file. The company’s words: “Our investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata had been disclosed without authorization.”
The counts come from Helpfeel, not from an attacker’s forum post. About 23.62 million user records, including anonymous accounts that had no name set. About 490 million image-metadata records. And a separate set of about 2.4 million images the attacker retrieved directly, which is why the company says it “cannot rule out the possibility that some private images may have been viewed by the third party.” Payment card numbers were not accessed. Helpfeel says it has closed the route in, fixed the flaw, suspended image delivery as a precaution while it worked, and invalidated authentication data on its side. It has asked every user to change their password. It has not said how the passwords were hashed.
What was exposed
The user table carried the account itself: name or nickname, email address, password hash, user and device IDs, login session IDs, X integration tokens, Google sign-in email, profile details, language, registration and login dates, subscription plan and billing status. Here is what each item is worth to whoever holds it:
- Email address and password hash. A hash is not the password, but a weak or reused password behind an ordinary hash is recovered in hours, and the pair is then tried at every bank, shop and email service on the internet. That is credential stuffing, and it is the main event of this breach.
- Session IDs and X tokens. A live session or token opens an account without any password at all. Helpfeel says it invalidated authentication data; if you had X connected to Gyazo, assume that link is burned and revoke it on X’s side too.
- Device IDs and login dates. Enough to make a fake “new sign-in on your device” email name your actual device and your actual last login.
- Subscription and billing status. Enough to tell a scammer which users pay, and to write “your Gyazo Pro renewal failed” to exactly those people.
The metadata table is the unusual part. Every image record carried the image ID that builds its URL, the IP address and browser that uploaded it, the location from the photo’s EXIF data, the text OCR read off the screenshot, the title, the page it was taken from, and a hash of the passphrase on private images. Screenshots are where people put the things they mean to send once: a chat, an address, a ticket confirmation, a password someone typed in the open, a bank balance. The recognised text of ten years of that is in the set, searchable, and tied to an IP address and an email.
What to do now
Most of this is about the password you used on Gyazo, and almost none of it is about Gyazo.
1. Change the Gyazo password, then change it everywhere else it was ever used. Not only where it is used now: the password from 2019 counts. A password manager will tell you where a password repeats; if you do not have one, this is the week to start. 2. Turn on the strongest sign-in every important account offers, starting with your email. A passkey where available, an authenticator app otherwise, and not SMS if there is a choice. A stolen password on its own then opens nothing. 3. Revoke Gyazo on X and Google. Go to the connected-apps page of each, by typing the address yourself, and remove Gyazo. Reconnect later if you want. 4. Expect the follow-up phish dressed as Gyazo. “Confirm your account after the security incident”, “your Pro renewal failed”, “a screenshot of yours was reported”: those messages will quote your real plan and real device because the data lets them. Do not click. Type gyazo.com yourself if you need to check anything. 5. Go through your Gyazo library and delete what should not be there. Look especially for screenshots that show a password, an address, an ID document or a ticket barcode. Deleting does not undo the leak, but it ends the window. 6. If the EXIF location data worries you, it should: a photo from your phone carries where it was taken. Turn location tagging off for the camera app, and stop uploading phone photos to a screenshot tool.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented this. The flaw was on Gyazo’s upload server, and no choice you make about your own inbox reaches into another company’s database. What an OptMsg account changes is what the stolen pair can be used for once it is out.
Two things. First, the login. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. The email-and-hash pair the attacker is holding is the login to Gyazo, not the login to your inbox, and there is no password on the account for a recovered hash to match. Your email is where most accounts get reset; keep that door shut and the rest stay shut with it.
Second, the wave. Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. With OptMsg’s patent-pending opt-in technology, the “confirm your Gyazo account” email from a domain you have not seen before lands in Trash rather than in front of you with your plan name in the subject. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert, so a real notice from a real company is not lost.
What that does not cover: the screenshots themselves, which are already out; a session token replayed against Gyazo, which is Helpfeel’s problem to have fixed; a phishing page you open yourself; a message from a sender you did approve whose own account was taken; a compromised device; or someone with your unlocked phone. Those are the six steps above.
If you want an inbox where a leaked password is not the master key, see how Security First works, or read why your inbox should not care about a leaked password.
Ready for an inbox that only holds the mail you asked for? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
What happened in the Gyazo data breach? On 11 September 2026 an attacker exploited a flaw in Gyazo’s image-upload server and reached its database. Helpfeel, the company behind Gyazo, detected it on 12 September, shut the access off, and disclosed it on 16 September, confirming about 23.62 million user records and 490 million image-metadata records were taken.
What information was exposed in the Gyazo breach? Names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google sign-in email, profile details, subscription plan and billing status. Image metadata included upload IP addresses, EXIF location data, the OCR text of screenshots, titles, source URLs and hashed private-image passphrases. Payment card numbers were not accessed.
Were passwords stolen in the Gyazo breach? Password hashes were, not plain passwords. Helpfeel has not said which hashing algorithm it used. A short or reused password behind a hash can be recovered, so change it on Gyazo and anywhere else it was used.
Were my private Gyazo images seen? Helpfeel says it cannot rule that out. About 2.4 million images were retrieved directly, and the metadata of every image, including the text read off it by OCR, was in the stolen records.
Would OptMsg have stopped the Gyazo breach? No. It happened on Gyazo’s servers. What OptMsg changes is the aftermath: there is no password on an OptMsg account for the leaked hash to match, and mail from a sender you have not approved goes to Trash rather than your Inbox, so the fake “confirm your account” email has a shorter path.
Sources
- Helpfeel: Notice regarding unauthorized access to Gyazo — 16 September 2026
- BleepingComputer: Gyazo server flaw exploited to steal 23.6 million user records — 18 September 2026
- SecurityWeek: 23 Million User Records Compromised in Gyazo Data Breach — 18 September 2026