Gyazo Data Breach Exposes 23 Million Accounts and OCR Screenshot Text

Helpfeel Inc. has confirmed a major security breach of its Gyazo screenshot and screen-recording platform, resulting in the theft of approximately 23.62 million user records. The incident, which began on September 11, 2026, stemmed from a vulnerability in an image upload server that allowed attackers to execute arbitrary commands.

While the leak of email addresses and password hashes is significant, the exposure of 490 million image metadata records presents a more complex privacy risk. This metadata includes upload IP addresses, EXIF location data, and—most critically—text extracted from screenshots via Optical Character Recognition (OCR). This OCR-processed data can reveal sensitive information that was never intended to be searchable, such as private addresses, login codes, or internal company communications captured in images.

Conceptual illustration of a server data leak and metadata exposure.
A vulnerability in an image upload server allowed unauthorized access to 490 million metadata records.

The Risk of “Searchable” Private Screenshots

The breach affects the core privacy model of Gyazo, where users often rely on the obscurity of a unique URL to keep their images private. According to Helpfeel Inc., the stolen metadata includes OCR-extracted text specifically impacting images uploaded in January 2019 or earlier. For users who used the platform to store sensitive documents or snippets of private conversations, this text is now potentially accessible to the attackers in a structured, searchable format.

In addition to the OCR data, the 490 million metadata entries include device IDs and X (formerly Twitter) integration tokens. These tokens could theoretically allow attackers to interact with linked social media accounts depending on the permissions granted at the time of integration. Helpfeel has noted that while the vulnerability was remediated by the early hours of September 12, the full scope of the data exfiltration was not publicly disclosed until September 16.

Data Scope and Mitigation Efforts

The company confirmed that the following categories of data were compromised during the exploit:

  • User Account Information: Email addresses, user IDs, and password hashes.
  • Integration Data: Device IDs and X (Twitter) integration tokens.
  • Image Metadata: Approximately 490 million records containing upload IPs, EXIF data, and OCR-extracted text.

Helpfeel has clarified that no credit card numbers or payment-method information were exposed, as these are handled by third-party processors. Furthermore, the company stated that its other services, including the Cosense (formerly Scrapbox) collaboration tool and the Helpfeel knowledge-management platform, were not affected by this incident.

To mitigate the ongoing risk, Gyazo has requested that all users change their passwords immediately. As a precautionary measure, the platform has also temporarily disabled viewing for a portion of images to prevent unauthorized access via leaked image IDs. This move aims to protect users whose “private” image links may have been included in the massive metadata haul.

The delay between the initial server “maintenance” on September 11 and the formal breach notification on September 16 suggests the company spent several days verifying the extent of the exfiltration. Users are advised to rotate passwords on any other services where they may have reused their Gyazo credentials and to remain vigilant for phishing attempts leveraging the leaked email addresses.

More From Category

More Stories Today