Gyazo Breach Exposes 23M Records and OAuth Tokens
Helpfeel confirms 23.6 million Gyazo accounts breached September 11, exposing Google and X OAuth tokens. Revoke app access before changing passwords.

Helpfeel, the company behind the Gyazo screenshot and image-sharing platform, confirmed on September 18 that an attacker exploited a vulnerability in its image upload server to steal records from 23.6 million user accounts and 490 million image metadata entries. The breach occurred September 11; Helpfeel discovered it the following day.
What was in the breach
User account records included names and email addresses, hashed passwords, user and device IDs, login session IDs, X (Twitter) OAuth integration tokens, and Google SSO credentials. Image metadata records included upload IP addresses, user agent strings, EXIF location data, and OCR-extracted text from uploaded images.
The OAuth and Google SSO credential exposure is the part that needs the fastest response. Those tokens can let an attacker access third-party services as the user without knowing the user’s password, and a password change does not invalidate existing tokens.
What to do
Revoke Gyazo’s third-party access before changing passwords. For Google, go to myaccount.google.com/permissions and remove Gyazo from connected apps. For X, go to Settings, then Security, then Apps and sessions, and revoke Gyazo’s access there.
After revoking tokens, change your Gyazo password. A reset closes out any active sessions tied to the old credential even if the hash is not yet cracked.
Watch for phishing and unexpected OAuth authorization prompts from services connected through Gyazo. Stolen tokens can be replayed against linked accounts.
The image metadata is not secondary
490 million image metadata records sounds like a footnote next to 23.6 million account records. It is not. OCR text pulled from screenshots can include internal URLs, code snippets, credentials, and confidential content that users never intended to keep. Upload IP addresses build a location history. Organizations that route internal screenshots through Gyazo should treat that metadata as potentially compromised and check whether any of those uploads contained sensitive material.
Company response
Helpfeel temporarily suspended Gyazo for maintenance, disabled access to affected files, and notified affected users. The company states there is no evidence the data was deleted, which points to exfiltration rather than vandalism. It reports no compromise of its Cosense product and has engaged external security experts and law enforcement. No specific CVE or technical root cause was disclosed for the underlying server vulnerability.
Related coverage: Revolut breach exposed passports and financial data | JSCeal malware bypasses Google auth with stolen cookies | IDScan sued after 153M driver licenses breached
Sources: BleepingComputer | SecurityWeek
Found this useful? Share it.


