Offgrid Studio logo Offgrid Studio

Privacy News

A Screenshot You Took in 2019 Just Became Part of a Data Breach

September 2026

Gyazo is one of those tools people forget they're using. Take a screenshot, it uploads automatically, you get a link to paste into a chat or a forum post, and you move on. Millions of people have done this for close to a decade — including, for many of them, back in 2019 or earlier. This week, some of those years-old screenshots became relevant again, for the worst possible reason.

Helpfeel, the Japanese company behind Gyazo, confirmed that an attacker exploited a vulnerability in its image upload server on September 11, ran arbitrary commands, and accessed the company's database before being locked out early the next morning. By the time it was over, the attacker had pulled 23.62 million user records and metadata tied to roughly 490 million images.

What was actually in the metadata

The account records are a fairly standard breach list — names, emails, password hashes, device and session IDs, connected X and Google SSO tokens, profile info, billing status. Helpfeel says no payment card numbers were involved. The more striking part is what came with the 490 million image records, most tied to uploads from January 2019 or earlier: OCR-extracted text pulled from inside the images themselves, upload IP addresses, EXIF location data where it existed, and — for images marked private — the hashed passphrases protecting them, plus a list identifying which images were private in the first place.

That combination matters because Gyazo links work by knowing an image's ID. Metadata that helps reconstruct those IDs can potentially be used to view images that were never meant to be public, regardless of how old they are. Helpfeel has temporarily disabled viewing for some images while it works through the fallout, and is asking users to change their password — on Gyazo and anywhere else they reused it.

The part worth sitting with

Most people don't think of a screenshot tool as holding sensitive data. It's not a bank, not a health app, not even a messaging app — it's just a place you dump images for a few seconds to grab a link. But OCR text, IP addresses, and location data quietly turn "just a screenshot" into something closer to a diary entry: what you were looking at, where you were, sometimes what the text on your screen said. None of that was sensitive to store in 2019. It became sensitive the moment someone else got access to it in 2026 — seven years later, with the person who uploaded it having long since forgotten it existed.

Try Offgrid Studio

It's the reason all four of our apps work the same way: nothing you capture or record gets uploaded anywhere by default, so there's nothing sitting on a server years from now to explain.

More from Offgrid Studio

Also read: We Ran Our Own Network Audit. Here's What We Found. and 50 Million People Thought Their AI Chats Were Private. They Weren't.

Back to the blog