Tendvane

← All articles

AccountsSeptember 19, 2026

A screenshot service lost 23 million accounts, and the links to 490 million images

Stop and think about what is actually in your screenshots. An order confirmation. A chat thread. A bank balance you were showing a relative. Half an email.

Gyazo, the screenshot and image sharing tool run by Kyoto company Helpfeel, was broken into on 11 September. An attacker found a flaw in the image upload server that let them run commands on it, and from there reached the database. Helpfeel spotted the intrusion that evening, cut the access and fixed the hole in the early hours of 12 September, reported it to the authorities on the 15th and told the public on the 16th. About 23.62 million user records went out of the door: names or nicknames, email addresses, hashed passwords, user and device IDs, login session IDs, X integration tokens, Google sign-in addresses, and subscription and billing status. No card numbers were in there.

The bigger number is the one nobody puts in the headline. Metadata for roughly 490 million images was taken too, and it includes the information used to build an image's URL. Also in there: the IP address the upload came from, EXIF location data, and OCR text, which is Gyazo's own reading of the words inside your pictures. Most of it dates from before January 2019, when people were pasting screenshots around with rather less thought than they might now.

Helpfeel is asking every user to change their Gyazo password and, more to the point, to change it anywhere else they used the same one. That second part is the whole game with a breach like this. If you have a rough idea which accounts share a password but no real list, Tendvane's privacy and accounts check will at least show you which accounts are signed in on your PC to start from.

Sources

Download Tendvane