← Back to Feed

Gyazo server flaw exploited to steal 23.6 million user records

September 18, 2026 · BleepingComputer · Severity: CRITICAL

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.

Key Takeaways

  • A server flaw in the Gyazo screenshot-sharing service was exploited to steal 23.6 million user records, including email addresses and hashed passwords, in what appears to be one of the largest data breaches targeting a cloud-based media service.
  • The attackers exploited a server-side vulnerability in Gyazo's API to extract the user database, though the company has since deployed patches and forced password resets for all affected accounts.
☕ Buy a Coffee