Skip to content
Back to Blog
high severity September 23, 2026 · 4 min read Unverified claim — what this is

Gyazo data breach: 23.6 million records leaked — what it means for you

If you are a customer of Gyazo, here’s what is being claimed, and what it would mean for you.

On 11 September 2026 attackers broke into Gyazo and took about 23.62 million user records plus hundreds of millions of image details, according to Helpfeel, the company that runs it. Emails, password hashes, and data that can point to screenshots were involved; payment cards and the image files themselves were not. The company is notifying users and still does not know how many unique people were affected, or whether any private images were viewed.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Gyazo data breach: 23.6 million records leaked — what it means for you

On 11 September 2026, someone broke into the servers Gyazo uses to receive uploaded images, got unauthorized access, and reached the user database. Helpfeel, the company that runs Gyazo, says staff spotted the activity that evening and closed the hole by the early hours of 12 September.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →

Watch Gyazo

Get alerted the next time Gyazo files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Gyazo’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.

Helpfeel’s own notice of 16 September 2026 says about 23.62 million user-related records were taken, along with about 490 million image-detail records (mostly for images registered on or before January 2019, about 14.4% of all image-related data) and another 2.4 million records pulled with extra filtering. No payment-card or other payment-method data was taken, and the image files themselves were not. The company told Japan’s privacy regulator on 15 September and is still investigating.

Why “your pictures weren’t stolen” is the wrong comfort

Most coverage will lead with two true statements: no credit-card numbers were taken, and the pictures themselves were not copied off the servers. For a normal person, that sounds like the dangerous part missed you. It is the wrong comfort, because of what Gyazo actually is.

Gyazo is how people send a picture of whatever is on their screen — a conversation, a ticket, a work document, a form — by creating a link. The attacker did not need to carry away the picture files. Helpfeel says they obtained the identifiers used to build those links, the text automatically read off many images, location data embedded in some photos, the internet address used to upload, and a list of which images had been marked private. The company then turned off viewing of some images for that reason. It still cannot rule out that some private images were opened.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

Sitting next to that index are the account records: names and nicknames people typed in, email addresses, scrambled passwords, login-session data, and, for some users, X/Twitter and Google connection details. The 23.62 million figure includes anonymous accounts with no registered email. Helpfeel does not yet know how many unique people that represents.

The honest read is not that a photo album was emptied. It is that a large catalog pointing at screenshots — plus the accounts used to post them — left the building. For a service built on “here is a link to what was on my screen,” that catalog is the sensitive object. If you never used Gyazo, this is not your incident. If you did, even years ago and even without creating a full account, it may be.

What to actually expect

  • A notice from Gyazo, by email if they have one on file, otherwise in the Gyazo website itself. User messages were still being prepared after the 16 September announcement, so silence so far does not mean you were spared.
  • Being signed out. The company cut off the stolen login data, so saved sessions and “keep me logged in” should stop working.
  • Some older screenshots not opening. Helpfeel temporarily disabled viewing of some images because the stolen identifiers can be turned into web links.
  • Copycat emails that pretend to be Gyazo and ask you to click a link, “check if you were affected,” or re-enter a password. The real company already has your address if it can email you, and it has already asked everyone to change passwords. It does not need you to send one.

What you can and cannot fix

The copy that was taken cannot be pulled back. If your details were among the 23.62 million records, your email address, the name or nickname you entered, the scrambled password, device and user IDs, login-session data, and (if you connected them) X/Twitter or Google sign-in details are out. The same is true of the image details: the identifiers that build Gyazo links, upload internet addresses, any location stored in a photo, titles, source links, and the computer-read text from images. Nobody can delete the attacker’s copy. If a private image was opened, that cannot be undone either — and Helpfeel still cannot say whether that happened. There is no reliable public check that can tell you whether you were in this specific incident; a “clean” result would not mean you were safe.

  • Change your Gyazo password now, and change it everywhere you reused it. Do this even if no email has arrived. The stolen set includes scrambled passwords, which can still be cracked, and the company has asked all users to do this.
  • If you ever linked X/Twitter or Google to Gyazo, disconnect that link and look at those accounts. Those connection tokens were in the stolen data for people who had connected them.
  • Do not count on old Gyazo links having stayed private — especially shots from 2019 or earlier, and anything you marked private. Helpfeel cannot rule out that some private images were viewed. If a screenshot showed something sensitive, treat that content as possibly seen. You cannot unspread it; you can stop using those links.
  • Shrink the rest of your public footprint. A leaked email and nickname become much more useful to a stranger when people-search listings have already attached relatives, phone numbers, employers, and previous addresses to the same name. Those directory listings, unlike the Gyazo dump, can actually be removed. The dump cannot.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Gyazo is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High contact details only, none of them permanent
Disclosed September 23, 2026
Last reviewed September 23, 2026
Affected Unconfirmed
Data exposed Names and nicknamesEmail addressesPassword hashesUser IDsDevice IDsLogin session IDsX/Twitter tokensGoogle sign-in emails +7 more
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email