Gyazo

Sep 2026 · Graded Attested · Technology and Software · Beyond the filings
GyazoSep 2026
Not yet quantified
AAttested
An unpatched flaw in Gyazo's own image upload server let an attacker run arbitrary commands and walk into the database behind it: 23.62 million accounts, their password hashes, and roughly 490 million image metadata records, most from links minted in 2019 or earlier. The upload server was never meant to be the database's front door, but nothing stood between the two to prevent it. The attacker also lifted the list marking which images were private, and Helpfeel cannot say those images went unseen. Calling an image link 'private' was a label, not an actual lock.
Technology and Software
Gyazo breach exposes 23.62 million user records and 490 million image records - PII and metadata exposed in huge attack
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete Beyond the Filings ledger ← Back to the index