If you have ever uploaded a screenshot to Gyazo, change your Gyazo password now and change it anywhere else you reused it. Gyazo's operator Helpfeel confirmed on September 16, 2026 that an attacker exploited its image upload server on September 11 and accessed roughly 23.62 million user records, including names, email addresses and password hashes.
What Happened in the Gyazo Breach
Gyazo is a screenshot and image sharing tool operated by Japanese software company Helpfeel. On September 11, 2026, an attacker exploited a vulnerability in Gyazo's image upload server that allowed arbitrary commands to be executed on the host. Helpfeel says the intruder was cut off the following day, but not before reaching a database of user records.
The scale is what makes this breach unusual for a tool most people think of as disposable:
- ~23.62 million user records containing account data
- ~490 million image metadata records tied to uploaded images
- Metadata that could be used to reconstruct image URLs, meaning uploads you assumed were unlisted may be reachable
Helpfeel published its notice and apology on September 16, 2026 and has asked all Gyazo users to change their passwords.
What Data Was Exposed
According to Helpfeel's disclosure and reporting on the incident, the exposed user records may include:
- Names and email addresses
- Password hashes (hashed, not plaintext — but still crackable offline for weak passwords)
- User IDs and device IDs
- X (Twitter) integration tokens for accounts that linked social login
- Profile information and usage statistics
- Billing information
Helpfeel states that payment card numbers were not compromised. Note also that the ~23.62 million figure includes anonymous accounts with no registered email address, so the number of identifiable individuals is lower — the company is still working out the exact count.
The Real Risk Is Password Reuse
Hashed passwords are not harmless. Attackers run offline cracking against leaked hashes, then replay the recovered email-and-password pairs against banking, email and shopping sites — an attack called credential stuffing. If your Gyazo password was also your email password, that is the exposure that matters most.
Step 1: Change Your Gyazo Password Directly
Go to gyazo.com yourself and change your password from your account settings. Do not click a password-reset link inside an email you received about the breach — breach announcements are immediately followed by fake notification phishing that copies the real wording. Type the address in yourself.
Step 2: Change Every Reused Copy of That Password
If the Gyazo password appears anywhere else, change it there too, starting with the accounts that can be used to reset everything else:
- Your primary email account
- Banking, brokerage and payment apps
- Cloud storage and password manager (if it shared the password)
- Social accounts, especially X if you used it to sign into Gyazo
Use a unique password for each one. A password manager makes this practical rather than theoretical.
Step 3: Revoke the Gyazo Connection on X
Because X integration tokens were in the exposed data, disconnect Gyazo from your X account: open X settings, go to Security and account access → Apps and sessions → Connected apps, find Gyazo and revoke its access. Revoking invalidates the token, which makes a stolen copy useless. Reconnect later if you still use the feature.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Turn On Two-Factor Authentication
Enable two-factor authentication on your email, financial and social accounts. Prefer an authenticator app or a hardware key over SMS codes, which can be intercepted through SIM-swap attacks. 2FA is what stops a cracked password from becoming an account takeover.
Step 5: Treat Your Old Uploads as Public
The exposure of around 490 million image metadata records means private-image access cannot be ruled out. Go through your Gyazo history and delete anything sensitive you uploaded and forgot about. In practice that often means:
- Screenshots of invoices, pay stubs, tax forms or medical documents
- Chat or email screenshots containing addresses and phone numbers
- Photos of ID cards, tickets or boarding passes
- Internal dashboards, API keys or config files captured in a screenshot
If a screenshot contained a credential, rotate that credential. Deleting the image does not un-leak what was already copied.
Step 6: Watch for Breach-Themed Phishing
Expect emails and DMs referencing the Gyazo incident and offering to "secure your account" or "verify your identity." Treat every link as hostile. Legitimate services never ask for your password by email, and no company involved in a breach will ask you to confirm card details to "restore" access.
Check Your Wider Exposure First
A leaked email address is rarely leaked once. Before you assume this is contained, run a free PrivacyOn scan to see which data brokers publish your name, address and phone number, and whether your credentials are already circulating on dark web marketplaces.
Why a Screenshot Tool Breach Still Matters
Gyazo did not hold Social Security numbers or card data, so the instinct is to shrug. That underestimates how breaches get combined. An attacker who has your email address from Gyazo, your home address from a people-search site, and your phone number from a third leak has enough to pass a customer-service identity check or build a convincing spear-phishing message. Each individually harmless leak raises the value of the others.
That aggregation problem is why removing your data from broker sites matters after any breach. PrivacyOn covers 100+ data broker and people-search sites, submits removals on your behalf, and re-submits automatically when your listings reappear. It also runs 24/7 dark web monitoring so you learn about a leaked credential from us instead of from a fraudulent charge. Family plans cover up to 5 people, with pricing from $8.33/month.
Frequently Asked Questions
Was I affected by the Gyazo data breach?
Assume yes if you ever created a Gyazo account or uploaded images while signed in. Helpfeel puts the exposure at roughly 23.62 million user records covering the account database, and has asked all users — not a subset — to change their passwords. Anonymous uploads with no registered email are included in that count, so the number of identifiable people is smaller.
Were Gyazo passwords stored in plaintext?
No. Helpfeel says password hashes were exposed, not plaintext passwords. Hashing slows attackers down but does not stop them: short or common passwords fall quickly to offline cracking, and any reused password should be treated as compromised.
Can someone see my private Gyazo screenshots?
Possibly. Around 490 million image metadata records were exposed, including information that could be used to reconstruct image URLs, and Helpfeel has said private-image access cannot be ruled out. Treat anything you uploaded as potentially viewable, delete sensitive screenshots, and rotate any credential that appeared in one.
Do I need to freeze my credit after the Gyazo breach?
This breach did not expose Social Security numbers or payment card numbers, so a credit freeze is not the urgent step here — password hygiene is. That said, a freeze at all three bureaus is free, reversible and sensible if your SSN has been exposed in any other breach, which for most US adults it has.
How do I check whether my email address is in this breach?
Search your inbox for Gyazo account emails to confirm you had an account, and check your email address against known breach collections. PrivacyOn's free scan checks your exposure across breach data and data broker listings in one pass, so you see credential risk and public-profile risk together.
What should I do if I reused my Gyazo password on my bank?
Change the bank password immediately from the bank's own app or typed-in website, enable two-factor authentication, and review recent transactions and login history. Then change that password everywhere else it was used, and set up alerts for new logins and transfers so an attempted takeover surfaces fast.