Gyazo Server Intrusion Puts Account Data and Private Image Links at Risk
Gyazo confirmed a critical upload-server flaw exposed 23.62M user records and 490M image metadata, risking private links, sessions and passwords.
Text generated by artificial intelligence, published without human review. AI transparency
Illustrative image generated with AI
Upload-server flaw opened a path into Gyazo’s backend
Helpfeel, the Japanese company operating the Gyazo screenshot and screen-recording platform, has confirmed unauthorized access to infrastructure supporting the service. The attacker reached approximately 23.62 million user records and about 490 million records containing image metadata.
The intrusion began on September 11, when the attacker exploited a vulnerability in Gyazo’s image upload server. The flaw allowed malicious command execution, giving the intruder access beyond the server’s intended upload functions and into backend data stores.
Helpfeel detected suspicious activity and blocked the attacker on September 12. By then, however, the user database and image-related metadata had already been accessed. The company temporarily took Gyazo offline while investigating the breach and applying remediation.
The exploited flaw is tracked as CVE-2026-91843 and carries a critical CVSS 3.1 score of 9.8. Its vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describing a remotely exploitable issue requiring neither authentication nor user interaction, with potentially high confidentiality, integrity, and availability impact.
Helpfeel has not disclosed the affected software versions, the vulnerable component’s architecture, or the exact commands executed by the attacker. No public patch version or standalone security update has been identified. The vulnerability’s CISA Known Exploited Vulnerabilities status and any associated remediation deadline are also not known.
The 23.62 million records are not necessarily 23.62 million people
The compromised database contained approximately 23.62 million account records, a figure rounded to 23.6 million in some reporting. That count should not be interpreted as an exact number of affected individuals.
Gyazo permits anonymous accounts that may lack registered email addresses or comparable contact information. One person could also be represented by more than one account or record. Helpfeel is therefore still calculating how many identifiable people had personal information exposed.
Depending on the account, the accessed fields may include:
- Names or nicknames
- Email addresses and Google SSO email addresses
- Password hashes
- User and device identifiers
- Login session IDs
- X integration tokens
- Profile and language settings
- Registration and last-login timestamps
- Subscription plans and billing status
- Usage statistics
Payment card numbers were not exposed. Reports referring broadly to billing information describe account-level subscription or billing status, not compromised credit-card data.
The presence of password hashes creates an offline cracking risk, particularly for users who chose weak passwords. The actual difficulty depends on the undisclosed hashing algorithm, its configuration, and whether individual salts or other protections were used.
Session IDs and X integration tokens present a different problem. If any remained valid after extraction, they could potentially support session abuse or unauthorized interaction with connected accounts without requiring the victim’s plaintext password. Helpfeel has not disclosed token lifetimes, whether all active sessions were invalidated, or whether stolen authentication data has subsequently been used.
Gyazo has roughly 23 million users worldwide and has received approximately 3.1 billion uploaded media items, according to reporting on the incident and the platform’s scale.
Image metadata could expose more than account identities
The breach extended well beyond conventional account information. The attacker accessed approximately 490 million image-metadata records, most associated with content uploaded in or before January 2019.
Those records may contain image IDs, upload IP addresses, User-Agent strings, titles, source URLs, OCR-extracted text and EXIF location data. Hashed passphrases for private images were also among the potentially exposed fields.
This combination creates several privacy paths. IP addresses can reveal network or approximate location information, while EXIF fields may contain more precise geolocation data. OCR text can expose information visible inside screenshots, including names, messages, internal system details or credentials captured by mistake.
Image IDs are especially consequential because they may allow someone to reconstruct corresponding Gyazo URLs. Content protected mainly by an unguessable link becomes vulnerable if the identifier required to recreate that link is obtained from a database.
A separate figure of approximately 2.4 million images has been reported for metadata accessed through specific attacker searches. That number appears in one account of the investigation and should not be confused with the wider pool of roughly 490 million metadata records.
The attacker also obtained a list identifying private images. Helpfeel has not confirmed that the underlying image files were downloaded, but it cannot rule out that some private images were viewed. There is no indication that content was deleted.
In response, the company disabled access to files where exposed metadata could provide an unauthorized route to the associated content. This reduces immediate access but does not reverse disclosure of metadata already taken.
Historical screenshots create present-day risks
Older uploads can remain sensitive long after their original use. A screenshot created years ago might still contain an active email address, an internal hostname, a customer record, source code or details useful for impersonating its owner.
The exposed data can also be combined across categories. An attacker could pair an email address with image titles, OCR text, device information, subscription status and past usage patterns. That context makes phishing messages more convincing than generic breach-themed email.
For example, a fraudulent notification could mention a real Gyazo account, an old image subject or a connected X account. It could then direct the recipient to a fake password-reset or account-verification page.
Corporate users face additional exposure if they uploaded screenshots of administrative panels, software defects, access tokens, internal communications or cloud consoles. Even when the screenshots themselves remain inaccessible, titles, source URLs and extracted text may reveal operational details.
Anonymous users are not automatically safe. They may be difficult for Helpfeel to contact, but their records can still include device IDs, session identifiers, IP addresses and image metadata. Helpfeel plans to use web-interface notices for users who cannot be reached by registered email.
Helpfeel has contained the known access route, but the investigation continues
Helpfeel says it blocked the routes used by the intruder and remediated the exploited image-upload-server vulnerability. It has also engaged external specialists, contacted authorities and begun sending notices to users with registered email addresses.
The company found no evidence that information was stolen from its other services or from Cosense systems. It has likewise not reported systematic downloading of Gyazo’s entire image collection.
Those findings remain provisional. The attacker has not been publicly identified, and the final number of affected people is still being established. Helpfeel may release further information as its forensic work progresses.
The incident represents a confirmed exploitation event rather than a theoretical vulnerability disclosure. The attacker successfully executed commands and reached backend records before containment, according to the reported sequence of compromise and response.
What Gyazo users and organizations should do now
Gyazo users should change their account passwords and replace the same or similar passwords anywhere else they were used. Password reuse can turn exposure of one hash into compromises across unrelated services.
Users should also terminate active Gyazo sessions and sign in again once Helpfeel’s account-security actions are complete. Connected X tokens and other integration credentials should be revoked or rotated where the relevant controls are available.
Additional precautions include:
- Review Gyazo accounts for unfamiliar access or changes.
- Watch connected X accounts for unexpected activity.
- Treat unsolicited password-reset and verification messages as suspicious.
- Verify breach-related communications through Gyazo’s official interface rather than embedded email links.
- Reassess sensitive screenshots, recordings and private images stored on the service.
- Remove or replace content that may remain reachable through exposed links.
- Monitor email accounts for targeted phishing based on real profile or image information.
Organizations should identify employees who used Gyazo with corporate email addresses or uploaded work-related screenshots. Accounts involving internal URLs, credentials, customer information, source code or administrative interfaces warrant additional monitoring and credential resets.
The absence of exposed card numbers limits direct payment fraud, but it does not make the breach low impact. Authentication data, integration tokens and image metadata provide several independent routes to account abuse, targeted deception and privacy loss.
Sources
This article is an original reworking based on the sources below.
