Gyazo data breach: 23.6 million records leaked — what it means for you
If you are a customer of Gyazo, here’s what is being claimed, and what it would mean for you.
On 11 September 2026 attackers broke into Gyazo and took about 23.62 million user records plus hundreds of millions of image details, according to Helpfeel, the company that runs it. Emails, password hashes, and data that can point to screenshots were involved; payment cards and the image files themselves were not. The company is notifying users and still does not know how many unique people were affected, or whether any private images were viewed.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On 11 September 2026, someone broke into the servers Gyazo uses to receive uploaded images, got unauthorized access, and reached the user database. Helpfeel, the company that runs Gyazo, says staff spotted the activity that evening and closed the hole by the early hours of 12 September.
Watch Gyazo
Get alerted the next time Gyazo files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Gyazo’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Helpfeel’s own notice of 16 September 2026 says about 23.62 million user-related records were taken, along with about 490 million image-detail records (mostly for images registered on or before January 2019, about 14.4% of all image-related data) and another 2.4 million records pulled with extra filtering. No payment-card or other payment-method data was taken, and the image files themselves were not. The company told Japan’s privacy regulator on 15 September and is still investigating.
Why “your pictures weren’t stolen” is the wrong comfort
Most coverage will lead with two true statements: no credit-card numbers were taken, and the pictures themselves were not copied off the servers. For a normal person, that sounds like the dangerous part missed you. It is the wrong comfort, because of what Gyazo actually is.
Gyazo is how people send a picture of whatever is on their screen — a conversation, a ticket, a work document, a form — by creating a link. The attacker did not need to carry away the picture files. Helpfeel says they obtained the identifiers used to build those links, the text automatically read off many images, location data embedded in some photos, the internet address used to upload, and a list of which images had been marked private. The company then turned off viewing of some images for that reason. It still cannot rule out that some private images were opened.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Sitting next to that index are the account records: names and nicknames people typed in, email addresses, scrambled passwords, login-session data, and, for some users, X/Twitter and Google connection details. The 23.62 million figure includes anonymous accounts with no registered email. Helpfeel does not yet know how many unique people that represents.
The honest read is not that a photo album was emptied. It is that a large catalog pointing at screenshots — plus the accounts used to post them — left the building. For a service built on “here is a link to what was on my screen,” that catalog is the sensitive object. If you never used Gyazo, this is not your incident. If you did, even years ago and even without creating a full account, it may be.
What to actually expect
- A notice from Gyazo, by email if they have one on file, otherwise in the Gyazo website itself. User messages were still being prepared after the 16 September announcement, so silence so far does not mean you were spared.
- Being signed out. The company cut off the stolen login data, so saved sessions and “keep me logged in” should stop working.
- Some older screenshots not opening. Helpfeel temporarily disabled viewing of some images because the stolen identifiers can be turned into web links.
- Copycat emails that pretend to be Gyazo and ask you to click a link, “check if you were affected,” or re-enter a password. The real company already has your address if it can email you, and it has already asked everyone to change passwords. It does not need you to send one.
What you can and cannot fix
The copy that was taken cannot be pulled back. If your details were among the 23.62 million records, your email address, the name or nickname you entered, the scrambled password, device and user IDs, login-session data, and (if you connected them) X/Twitter or Google sign-in details are out. The same is true of the image details: the identifiers that build Gyazo links, upload internet addresses, any location stored in a photo, titles, source links, and the computer-read text from images. Nobody can delete the attacker’s copy. If a private image was opened, that cannot be undone either — and Helpfeel still cannot say whether that happened. There is no reliable public check that can tell you whether you were in this specific incident; a “clean” result would not mean you were safe.
- Change your Gyazo password now, and change it everywhere you reused it. Do this even if no email has arrived. The stolen set includes scrambled passwords, which can still be cracked, and the company has asked all users to do this.
- If you ever linked X/Twitter or Google to Gyazo, disconnect that link and look at those accounts. Those connection tokens were in the stolen data for people who had connected them.
- Do not count on old Gyazo links having stayed private — especially shots from 2019 or earlier, and anything you marked private. Helpfeel cannot rule out that some private images were viewed. If a screenshot showed something sensitive, treat that content as possibly seen. You cannot unspread it; you can stop using those links.
- Shrink the rest of your public footprint. A leaked email and nickname become much more useful to a stranger when people-search listings have already attached relatives, phone numbers, employers, and previous addresses to the same name. Those directory listings, unlike the Gyazo dump, can actually be removed. The dump cannot.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Anywhere Real Estate 17K Records — February 2026
Real-estate brokerage Anywhere Real Estate disclosed a breach exposing PII for approximately 17,000 …
ADT 5.5–10 Million Customer Records Disclosed — April 2026
ADT confirmed unauthorized access to between 5.5 and 10 million customer records in April 2026. Expo…