← Back to Feed
Gyazo server flaw exploited to steal 23.6 million user records
September 18, 2026 · BleepingComputer · Severity: CRITICAL
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
Key Takeaways
- A server flaw in the Gyazo screenshot-sharing service was exploited to steal 23.6 million user records, including email addresses and hashed passwords, in what appears to be one of the largest data breaches targeting a cloud-based media service.
- The attackers exploited a server-side vulnerability in Gyazo's API to extract the user database, though the company has since deployed patches and forced password resets for all affected accounts.