THE TELL

Gyazo: 490 million screenshots leaked their upload location, and nobody remembered taking them

A screenshot tool popular with gamers lost 23.6 million user records. The scarier part is the other number: 490 million image records, most from before 2019, with upload IP addresses and EXIF location data attached.

Gyazo is one of those tools you install once and forget. You hit a key, it grabs a piece of your screen, uploads it to the cloud and hands you a link you paste into a chat. Millions of people use it exactly that way — the company claims 23 million users worldwide, who have submitted 3.1 billion media items.

On September 11, 2026, someone got into the database. Gyazo, operated by Helpfeel, says attackers exploited a server vulnerability and took roughly 23.62 million user records. The company noticed suspicious activity on September 12 and patched the hole — after the data was already gone. The service is now offline "temporarily suspended for maintenance as a preventive measure."

What it means

The user records are the ordinary half of this: names and nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, usage statistics. Change your password, change it everywhere you reused it, done. The other half is what makes this different from a normal breach.

Gyazo says the incident also exposed 490 million image metadata records, most tied to images uploaded before January 2019. Metadata is the invisible label attached to a file. In this case it includes the image IDs used to build the image URL, the IP address the upload came from, the User-Agent string that says what browser and device you used, EXIF location data, text pulled out of the picture by OCR — the machine reading of whatever words were visible on your screen — plus image titles and source URLs.

Read that list again slowly. A screenshot you dropped into a Discord chat in 2017 may now sit in someone's copy of a database, attached to where you were, what device you used, and a typed-out transcript of every word visible in the frame.
Share this

And the company is explicit that the image IDs can potentially be used to reach the actual content, which is why it temporarily disabled access to files whose records were exposed. Private images had hashed passphrases in the same dataset, and Gyazo says the attackers also obtained a list identifying which images were private — and it cannot rule out that some were viewed. That is an unusually honest sentence for a breach notice, and an unusually unpleasant one.

Who it matters to

Anyone who has ever pasted a Gyazo link into a game chat, a forum thread or a support ticket — which, if you were a teenager on Discord between 2015 and 2019, is probably you, and you have no memory of what was in those frames. It hits students and people early in their careers hardest: the screenshots you took to show a friend a funny message may also contain a half-visible bank balance, a rental address, a work login screen, a DM thread. It also hits everyone who screenshots things for work — freelancers, support staff, people who send clients proof of payment. And there is a quieter group: people who used Gyazo's private image feature precisely because they wanted something not public. Gyazo says it cannot rule out that some private images were viewed.

What's next

Two concrete things to watch. First, whether Gyazo comes back online at all and in what shape — the platform is down and the company says only "please wait a little longer until recovery," with no date given. Second, the notifications: the firm says it is contacting affected users directly while investigating with external experts, and it has contacted the authorities. Gyazo did not say what share of the exposed records are anonymous accounts, and did not name which authorities. Beyond that, no timeline has been published.

One detail to hold on to

The user data is from people who chose to sign up. The 490 million metadata records are mostly from before January 2019 — files from an era when nobody thought of a screenshot as a document about themselves. We treat images as things we send. The database treated them as things that describe us, and kept them for seven years.

Sources: Bleeping Computer, "Gyazo server flaw exploited to steal 23.6 million user records," by Bill Toulas, September 18, 2026; Gyazo/Helpfeel statement and post on X cited therein.

Why we ran this7/10

Скриншоты, которые люди годами кидали в чаты, оказались привязаны к почтам, IP и координатам съёмки — и всё это утекло разом у 23,6 млн человек.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Loudoun County cut property taxes 30%. I…Next: Three guys, a broken photo, and $3,000 of … →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X