Security News

Gyazo Breach Exposes 490 Million Metadata Records, Raising Screenshot Privacy Fears

Infosecurity Magazine · 21 Sept 2026
Key Takeaway Businesses should avoid using screenshot tools to share sensitive information such as credentials or internal system details, and should review any historical Gyazo uploads for exposed data.

Japanese image-sharing service Gyazo has disclosed a major data breach that exposed nearly 24 million customer records after attackers exploited a vulnerability in an upload server. Alongside this, a further 490 million metadata records tied to images were exposed, including image IDs, source IP addresses, user agent details, location data, OCR text extracted from images, titles, source URLs, and hashed passphrases.

Security experts have warned this metadata could carry serious risks. Because Gyazo is widely used by developers to share screenshots, exposed images may contain terminal output, API keys, credentials, and internal application details. The OCR feature, which makes captures searchable, also stored the text visible in those screenshots, meaning sensitive information could now be searchable by attackers rather than hidden inside an image. Combined with location data extracted from images, experts say attackers could potentially reconstruct user behaviour and movement patterns over time.

Gyazo developer Helpfeel confirmed that exposed metadata could be used to access and view corresponding images without authorisation, and has temporarily disabled viewing of some images as a precaution. While some experts noted the exposed data relates to images registered in or before January 2019, others maintain that the scale and nature of the metadata still represent a significant privacy and security concern.

data breach metadata exposure Gyazo privacy third-party risk
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.