Gyazo Data Breach Exposes 23.6M User Records

Gyazo breach exposes 23.6m user records and vast metadata trove

The Gyazo data breach has exposed 23.6 million user records and around 490 million metadata records. Confirmed on 17 September 2026, the incident raises questions about account security and the information associated with screenshots stored or shared through the service.

Gyazo is widely used to capture and share screenshots, screen recordings and visual content. Organisations now need to establish whether employees have used the platform for work and whether captured material may have included confidential information.

What happened in the Gyazo data breach?

Gyazo confirmed that a security breach affected two substantial sets of data. The first contains 23.6 million user records, while the second comprises approximately 490 million metadata records.

The reported figures describe records rather than confirmed numbers of individual people. One person may be represented by multiple database entries, particularly within the metadata collection. Even with that distinction, the scale indicates that a significant volume of account and service information was involved.

The disclosure was reported on 17 September 2026. The available report does not establish when the unauthorised access began, how long it continued or when Gyazo first detected the activity. It also does not provide a detailed incident timeline covering containment, investigation and customer notification.

No particular desktop application, browser extension, mobile application or software version has been identified as the sole affected product. On the information currently available, organisations should treat this as a breach involving the Gyazo service and its stored records, rather than a vulnerability limited to a specific local version.

What information was exposed?

The confirmed categories are user records and metadata records. However, the report does not provide a complete field-by-field description of the exposed databases.

It is therefore important not to assume that every possible account field was compromised. The reported material does not confirm whether exposed user records included email addresses, usernames, password hashes, authentication tokens, billing details or other account attributes.

Similarly, the presence of 490 million metadata records does not by itself confirm that 490 million screenshot files or images were accessed. Metadata is information associated with a file, account or activity. Depending on how a service structures its systems, it can describe items such as ownership, identifiers, creation details, file properties or sharing activity.

The precise metadata fields involved in the Gyazo data breach have not been publicly detailed in the supplied report. This limits the ability to determine whether individual records could reveal relationships between accounts, uploaded captures and shared links.

Who may be affected by the Gyazo data breach?

The directly affected population consists of people whose information appears within the 23.6 million user records and the users or content associated with the 490 million metadata records. Gyazo has not provided, in the available reporting, a breakdown by country, account type or business sector.

Potentially affected organisations are not limited to those that formally adopted Gyazo. Employees may have created individual accounts or used screenshot-sharing tools without central approval, including for technical support, collaboration or documenting software issues.

A business assessment should therefore consider several groups:

  • Current employees who use or previously used Gyazo for work-related screenshots.
  • Former employees whose accounts may still contain captures or account information connected to the organisation.
  • Contractors, suppliers and support providers who may have exchanged Gyazo links with staff.
  • Teams that use screenshots to document internal systems, customer enquiries, development work or administrative processes.

Business risk depends heavily on what each user captured and shared. Screenshots can unintentionally contain customer details, internal messages, account names, browser tabs, system addresses, access instructions or portions of business applications.

The available information does not confirm that screenshot contents were included in the exposed data. Nevertheless, organisations should assess that possibility carefully because the breach includes a very large set of metadata associated with the service.

How did the Gyazo breach happen?

The reported disclosure does not identify the initial access method. There is no confirmed information in the supplied material about whether the incident involved a software vulnerability, compromised credentials, a misconfigured database, an exposed interface or unauthorised access through a third party.

No vulnerability identifier or technical advisory has been cited. There are also no affected version ranges or patch instructions in the available report. Users should be cautious about unsupported claims that attribute the Gyazo data breach to a specific exploit until Gyazo publishes further technical findings.

The current exploitation status is also unclear. The confirmation establishes that records were exposed, but the supplied reporting does not state whether the data has been publicly released, offered for sale or used in subsequent phishing, account takeover or extortion attempts.

This distinction matters. Exposure establishes that confidentiality was lost, while confirmed misuse would demonstrate a further stage of harm. Organisations should monitor for both, without treating unverified claims as established facts.

Why the exposed records matter

The combination of user data and metadata may allow attackers to create convincing messages that refer to a real service or activity. If contact or account identifiers are among the exposed fields, affected users could receive phishing messages presented as password reset requests, breach notices or shared screenshot alerts.

Reused passwords would create an additional risk if authentication data was involved, although the report does not confirm that passwords or password hashes were exposed. Metadata may also provide context that makes social engineering more credible, even when it does not contain the underlying screenshot.

What organisations should do now

Organisations should begin with a targeted review of Gyazo use rather than a broad, generic response. The immediate objective is to identify potentially affected accounts and understand what business information those users captured.

  • Ask staff whether they have used Gyazo for organisational work, including through personal accounts.
  • Review approved software inventories, browser extensions and available web access records for evidence of use.
  • Require identified users to change their Gyazo passwords, particularly where passwords were reused elsewhere.
  • Enable two-factor authentication where it is available and review active account sessions and connected applications.
  • Ask users to inspect stored screenshots and recordings for confidential, personal or security-sensitive information.
  • Monitor identified users for phishing messages or unusual account activity referring to Gyazo content or shared links.

If a review finds screenshots containing personal data, credentials or confidential material, the organisation should document what was present and assess the consequences if it became accessible. Any regulatory or contractual response should be based on confirmed exposure and the organisation’s own findings.

Originally reported by Cybernews.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call