GYAZO , a Japanese image-sharing service, disclosed a breach on 11 September 2026 after attackers exploited a vulnerability in an upload server. Nearly 24 million customer records were exposed, along with a further 490 million image-related metadata records. The data reportedly included image IDs, source IP addresses, user-agent details, EXIF location data, OCR-extracted text, titles, source URLs and hashed passphrases.
Helpfeel, Gyazo’s developer, said on 16 September that some of this information could be used to construct image URLs and view images without authorisation, so it temporarily disabled access to some images.
Security experts warned that screenshots may contain terminal output, API keys, credentials, internal application screens and sensitive documents, while OCR could make visible text searchable. Location data could also reveal home, workplace or frequently visited locations. However, Filigran’s Damian Skeeles said the affected images were registered in or before January 2019, potentially reducing the current risk from exposed secrets.
Helpfeel said it had fixed the exploited vulnerability and urged users to change their Gyazo passwords, as well as any reused elsewhere. It also warned users to watch for suspicious follow-up emails. Experts said exposed email and identifying information could support convincing phishing attempts, including malicious links and scams.