Data Breaches · Credential Theft

Gyazo Leak Exposes Passwords and Image Links

Gyazo said a breach of its image upload server exposed 23.62 million user records and 490 million image metadata records, mostly for captures from January 2019 or earlier. Helpfeel, which runs Gyazo, said the attacker ran arbitrary commands on its systems and reached the database.

The critical part is the image-link IDs: Gyazo builds each private capture URL from a 32-character ID, and Helpfeel said those IDs could be used to view images without permission. That means the exposure is not just account data; old shared captures can remain reachable if someone has the link or learns the ID, even after a password change.

For teams that used Gyazo links or embedded captures, the lingering exposure sits in the URLs themselves. The report also says some authentication data was invalidated, but it does not say which session or integration tokens were killed, so the full cleanup picture is still incomplete.

5 sources · 15h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: Gyazo Leak Exposes Passwords and Image Links

More from today