Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Digested week: BuzzBallz signed by Tory leader builds excitement for conference | Lucy Mangan

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    Gyazo server flaw exploited to steal 23.6 million user records

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Digested week: BuzzBallz signed by Tory leader builds excitement for conference | Lucy Mangan
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • Gyazo server flaw exploited to steal 23.6 million user records
    • CFTC crypto market regulation enters White House review
    • Scientists discover cells that cheat death and rebuild damaged tissue
    • Hanwha Ocean’s design solution allowing LNG carrier’s switch to ammonia gets ABS’ thumbs-up
    • Judge Denies Efforts to End Oversight of Maricopa County Sheriff’s Office — ProPublica
    • Review: Rozina Ali’s ‘Seasons of Fury’ Sheds New Light on Islamophobia Before and After 9/11
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Gyazo server flaw exploited to steal 23.6 million user records

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 18, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.

    Gyazo is a cloud-based screenshot and screen-recording tool operated by Helpfeel that automatically uploads user screen captures to the cloud and gives them a shareable link to share on chats, forums, social media, etc.

    It’s especially popular in gaming communities and claims 23 million users worldwide, who have submitted 3.1 billion media items.

    According to an announcement by the company, the incident occurred on September 11, 2026, allowing attackers to access its database and obtain approximately 23.62 million user records.

    The company has now taken the platform offline while it conducts maintenance.

    “Currently, the Gyazo service is temporarily suspended for maintenance as a preventive measure. We sincerely apologize for any inconvenience caused. Please wait a little longer until recovery,” reads a post on X.

    The company detected the suspicious activity on September 12 and fixed a vulnerability the attackers used to breach the platform, but by then, the data had already been stolen.

    “Our subsequent investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata associated with uploaded images had been disclosed without authorization,” confirmed Gyazo in a statement published earlier this week.

    Based on Gyazo’s investigation, the data that has been exposed varies per user and may include one or more of the following:

    • Names/nicknames
    • Email addresses
    • Password hashes
    • User and device IDs
    • Login session IDs
    • X integration tokens
    • Google SSO email addresses
    • Profile details
    • Subscription information
    • Billing status
    • Usage statistics

    The exposed dataset includes anonymous account records, though Gyazo did not share what percentage those represent.

    The platform also stated that the incident exposed 490 million image metadata records, most associated with images uploaded to the service before January 2019.

    These metadata include image IDs used to construct image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images.

    Helpfeel notes that image IDs can potentially be used to access the corresponding content, which is why the company has temporarily disabled access to files whose records were exposed.

    Additionally, it stated that the hackers also obtained a list identifying private images, and the company cannot rule out that some were viewed.

    The firm said its investigation has not found signs of data being deleted due to this incident.

    The company also found no evidence that its other Helpfeel and Cosense services had data stolen.

    The firm is notifying affected users directly as they conduct an investigation with external experts, and have contacted the authorities.

    All Gyazo users are advised to change their passwords on the service and other platforms where they use the same credentials, and remain alert for suspicious communications.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Exploited Flaw Gyazo Million records server Steal User
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

    In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

    Secure enterprise sharing with access reviews for Microsoft 365

    Webinar: Which Google Workspace security controls actually matter?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Digested week: BuzzBallz signed by Tory leader builds excitement for conference | Lucy Mangan

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    Gyazo server flaw exploited to steal 23.6 million user records

    September 18, 2026

    CFTC crypto market regulation enters White House review

    September 18, 2026
    Latest Posts

    Texas deputy used 83K Flock cameras to find woman who had abortion. Was it a welfare check, as he claimed?

    August 4, 2026

    Trump’s Seabed Mining Order Is an Ecological and Political Disaster

    August 4, 2026

    ExxonMobil picks Sercel technology to support operations offshore Guyana

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Digested week: BuzzBallz signed by Tory leader builds excitement for conference | Lucy Mangan

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    Gyazo server flaw exploited to steal 23.6 million user records

    September 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.