Gyazo Breach: 23.6 Million Records and 490 Million Image Metadata Exposed in SaaS Service
Helpfeel, the operator of the Gyazo screenshot service, has confirmed unauthorised access via a vulnerability in its image upload server. User records and image metadata, including text extracted by OCR, were exposed.

News summary
Helpfeel has confirmed that on 11 September 2026, a third party exploited a vulnerability in the image upload server of Gyazo—its cloud-based screenshot and screen recording service—to gain unauthorised access to its systems and execute commands. The company blocked the access routes and patched the vulnerability the following day.
Approximately 23.62 million user records were affected—depending on the account, including names or aliases, emails, password hashes, session identifiers, and integration tokens—along with some 490 million image metadata records, mostly from images uploaded prior to January 2019. The company states that the images themselves and payment data were not compromised, and the number of affected individuals is still being determined.
The most sensitive aspect concerns the metadata: this includes EXIF data, text recognised by OCR, and image identifiers which, according to published analyses, could allow URLs to be reconstructed and parts of the content viewed. A screenshot of an internal dashboard, an email, or an invoice can contain significantly more information than meets the eye.
For businesses, the lesson lies in SaaS governance: seemingly harmless tools, adopted by employees without IT oversight, can accumulate sensitive information for years outside of any corporate control.
Source: ThreatPaper — 25 September 2026
Frequently Asked Questions
- Were user images stolen?
- According to Helpfeel, the image files themselves were not lost. However, image metadata was accessed, which includes information such as EXIF data and text extracted by OCR.
- What should a company do if its employees were using Gyazo?
- Affected passwords should be changed, integrations revoked, and a risk assessment performed on what information might have been exposed in screenshots. This is also an opportunity to review which SaaS tools are currently being used without oversight.
Concepts mentioned in this article: Cloud · SaaS · Vulnerability
Every cloud tool your employees use is another location where your data resides. At Seintec, we help you audit, control, and secure the use of SaaS services. Contact our cybersecurity team today.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.