TTO-2026-0919-140 · September 19, 2026 Data Breach

Gyazo Screenshot Service Breach Exposes 23.6 Million User Records Through Server Vulnerability

gyazo.com23.6 million user recordsServer-side vulnerabilityUsernames / emails / hashed passwords / upload metadataGyazo Inc. / Nota Inc.

Summary

Gyazo, the screenshot and screen-recording sharing service operated by Nota Inc., has disclosed a data breach in which an attacker exploited a server-side vulnerability to access and steal approximately 23.6 million user records. The exposed data includes usernames, email addresses, hashed passwords, and metadata associated with user uploads. Gyazo has approximately 10 million registered users; the discrepancy between the user count and the record count suggests that deleted accounts, session records, or other non-primary user records were included in the extracted dataset. The company has notified affected users, invalidated existing passwords, and is requiring password resets on next login.

Timeline

DateEvent
September 2026Attacker exploits server-side vulnerability in Gyazo infrastructure and extracts user database records
Sep 18-19, 2026Gyazo / Nota Inc. publicly discloses breach; notifies affected users; forces password reset on next login; investigation ongoing

What Happened

Gyazo is a widely used lightweight tool for capturing, annotating, and sharing screenshots and short screen recordings, particularly popular among developers, gamers, and technical support communities. The breach occurred through a server-side vulnerability in Gyazo’s infrastructure. The company has not disclosed the specific vulnerability class or how long the attacker had access before detection.

The 23.6 million record count is notable: Gyazo has approximately 10 million registered users, meaning the database accessed contained records beyond current active accounts — potentially deleted accounts, historical session data, or auxiliary tables. Gyazo stores passwords using hashing rather than plaintext, which limits immediate credential exposure but does not eliminate risk from offline cracking against weak passwords. Users who shared passwords across services should treat those credentials as compromised and change them on all affected platforms.

Domain Intelligence

gyazo.com — 62.07

gyazo.com scores in the low-trust range at 62.07. Gyazo is the breached service and the party that disclosed the incident. The score reflects gyazo.com’s domain trust posture prior to this breach disclosure.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 19, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026