Helpfeel Inc., the Japanese company behind the screenshot-sharing tool Gyazo, disclosed that hackers accessed and exfiltrated approximately 23.62 million records tied to Gyazo user accounts. The stolen data included names, email addresses, password hashes and device identifiers, but the detail drawing the most attention is what the attackers pulled from inside the screenshots themselves: GPS coordinates and other location data embedded in image files, some of them years old. Helpfeel confirmed the intrusion on September 16, 2026, after tracing suspicious activity back to a vulnerability in the server that handles image uploads.
Gyazo works by letting users capture a screenshot and instantly generate a shareable link, a workflow used heavily by developers, support teams and anyone documenting a bug or a webpage. That convenience also means years of screenshots sat on Helpfeel’s servers carrying whatever metadata the original device attached to them, largely unnoticed until the breach exposed exactly what had been quietly stored alongside every image.
An Upload-Server Flaw Gave Attackers a Path Into the Database
Helpfeel traced the intrusion to a vulnerability in Gyazo’s image upload server, which let an outside party run commands on the company’s systems and ultimately reach the Gyazo user database. The company said it first noticed abnormal activity on the evening of September 11, Japan time, and had blocked the access routes, severed the attacker’s connection, and patched the flaw by the early hours of September 12.
That response window, under 24 hours from detection to containment, is fast by breach-response standards, though it does not undo what the intruder already copied before the door closed. Helpfeel’s notice makes clear the exposure happened during that window, not on an ongoing basis after the patch went in.
23.6 Million Records Included Passwords, IDs and Billing Details
Helpfeel’s breach notice puts the confirmed number of disclosed Gyazo-related records at approximately 23.62 million. The compromised fields include user names, email addresses, hashed passwords, user and device IDs, tokens tied to X (formerly Twitter) account integration, profile details, usage statistics and billing information tied to paid accounts.
Password hashes are not the same as plaintext passwords, but a hash can still be cracked with enough computing time, particularly for weaker or reused passwords. Helpfeel told affected users to change their Gyazo password and to change the same password anywhere else they had reused it, a standard but necessary instruction given how many people repeat login credentials across services.
Old Screenshots Carried GPS Coordinates Nobody Remembered Storing
Separate from the account records, Helpfeel said the intrusion also touched image metadata tied to roughly 490 million Gyazo-hosted images, most of them uploaded in 2019 or earlier. That metadata included EXIF location data when a device had embedded GPS coordinates in the original screenshot file, along with text the service had extracted from images through optical character recognition.
Few users think about the fact that a screenshot can carry a device’s location baked into its file structure, especially years after uploading it and forgetting about it entirely. A phone camera’s photo library often strips or asks about location tagging, but a quick screen capture rarely triggers the same privacy prompt, which is how location data from 2019 or earlier ended up sitting untouched until this breach pulled it back into view.
The Breach Adds Gyazo to a Growing List of Screenshot-Tool Incidents
Screenshot and clipboard tools have become an attractive target because they sit outside the security scrutiny applied to email or banking platforms, while still accumulating sensitive content over years of casual use. A report from The Hacker News on the incident noted that the scale of exposed image metadata, not just account credentials, sets this breach apart from a typical login-database leak. Gyazo has operated since 2011 and built its user base largely on free, frictionless sharing, the same design choice that let so many screenshots accumulate on Helpfeel’s servers for well over a decade without anyone auditing what metadata rode along with them.
Helpfeel said it is continuing to investigate the full scope of the intrusion and has advised users to watch for phishing attempts that reference their Gyazo account or the breach itself, since stolen email addresses paired with real account details make for convincing scam bait. The company has not said whether it will notify individual users whose location data was specifically exposed, as opposed to issuing the broader public disclosure it made on September 16. Security researchers reviewing the incident have pointed out that OCR text pulled from old screenshots can be just as revealing as GPS coordinates, since a screen capture of an email, a spreadsheet or a chat window often contains names, account numbers or addresses nobody intended to publish.
For paid Gyazo subscribers, the exposure of billing information adds a second layer of risk beyond password reuse. Helpfeel has not detailed whether full payment card numbers were among the compromised billing fields or whether the exposure was limited to account-level subscription records, a distinction that matters for anyone deciding whether to also contact their card issuer. Users who uploaded screenshots from a work computer face a further wrinkle: location and OCR data tied to an old screenshot could just as easily reveal an employer’s office address or internal system details as a personal one.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview