Independent tech news and plain advice
Technologicall

Security

Gyazo Breach Exposes 23.6 Million Accounts and Photo Location Data

The screenshot app says attackers used a server flaw to take user records and details from hundreds of millions of images.

A woman working on a laptop at a desk in a home office
Photo: Shixart1985, CC BY 2.0, via Wikimedia Commons.

Gyazo, a popular screenshot and screen recording app, has confirmed a large data breach. The Japanese company behind it, Helpfeel, says attackers took about 23.6 million user records.

What Happened

Attackers used a flaw in a Gyazo server on September 11. The company spotted the activity the next day, fixed the flaw and briefly shut down the service to be safe. It is now contacting affected users.

What Was Exposed

The stolen user records include names or nicknames, email addresses, scrambled passwords, device IDs and session IDs. Tokens that link Gyazo to X accounts were taken too. So were Google sign-in emails, billing status and usage stats.

Separately, details from about 490 million images were exposed. That includes the IP address used to upload each image, location data stored inside photos and text the app had read from images.

Gyazo says passwords were hashed, which means they were stored in a scrambled form. It did not say which method it used, so it is safest to treat them as at risk.

Why It Matters

Stolen emails and password hashes often get used to break into other accounts where people reused the same password. Location data inside images could also show where someone took a photo.

What to Do

  • Change your Gyazo password, plus any other account that shares it.
  • If you linked X to Gyazo, remove Gyazo from your X connected apps.
  • Watch for phishing emails that mention Gyazo or your screenshots.
  • Turn on two-step sign-in wherever you can.

Questions Readers Ask

What is Gyazo?

Gyazo is a tool for taking and sharing screenshots and short screen recordings. It is popular with gamers and remote workers.

Is my password safe?

Gyazo stored passwords in a scrambled form called a hash, but it did not say which method it used. Change your Gyazo password and any other account that used the same one.

Where This Came From

We confirmed the facts in this story against these reports. The words above are our own.

Keep Reading