# Gyazo breach exposed metadata for 490 million images

_Published Monday, September 21, 2026 at 2:22 PM EDT · Security · Latest · Tier 1 — Major_

![Gyazo breach exposed metadata for 490 million images — Primary](https://assets.infosecurity-magazine.com/webpage/og/a7bbebfb-9b07-484f-884d-5303523fc5d1.jpg)

A breach at screenshot-sharing service Gyazo exposed nearly 24 million customer records and an additional 490 million image-metadata records, Infosecurity Magazine reported. Attackers exploited an upload-server vulnerability, gaining data that included image IDs, source IP addresses, location information, extracted text, source URLs and hashed passphrases.

Developer Helpfeel said some metadata could be used to construct image URLs and view corresponding images without authorization, prompting it to disable access to some images temporarily. The company remediated the vulnerability and urged password changes. Much of the affected image data dates from January 2019 or earlier, reducing the usefulness of some exposed credentials.

## Sources

- [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/experts-gyazos-breach-490-million/)

---
Canonical: https://techandbusiness.org/newswire/j9vF5KbzifHa4K5rR9IRmu
Published: 2026-09-21T18:22:03.318Z
Story chronology: 2026-09-21T09:30:00.000Z
Retrieved: 2026-09-21T20:31:59.191Z
Publisher: Tech & Business (techandbusiness.org)
