Mind the Breach

Gyazo breach: Your old screenshots never disappeared

Samuel Hill, Product Marketing at MIND

Sep 29, 2026

A screenshot tool no one approved just exposed seven years of pasted dashboards, errors and OCR'd text.

Somewhere in your company this week, someone screenshotted a dashboard, an error message or a Slack thread and pasted it into a free tool nobody in security ever approved. Gyazo just showed what happens to that image afterward. On September 11, an attacker exploited a vulnerability in the screenshot tool's upload server, ran commands on its systems and pulled records on 23.62 million users, according to Helpfeel, Gyazo's parent company. The image data went further: 490 million metadata records, some tied to screenshots uploaded before 2019, according to Helpfeel's own breach notice.

What did seven years of screenshots actually contain?

Helpfeel's notice confirms the stolen metadata included OCR text extracted from every screenshot, plus the upload IP address and EXIF location data pulled straight from the image file. The user records also included password hashes and the third-party integrations each account had connected. BleepingComputer reported that most of the 490 million image records came from uploads before January 2019, which means some of that extracted text had been sitting untouched in Gyazo's database for the better part of seven years. Help Net Security noted the company has not been able to rule out that the attacker viewed private images directly, not just the metadata describing them.

None of that started as a security failure inside your company. It started with someone needing a fast way to show a colleague what was on their screen. Gyazo was one click away. Nobody had to install anything a laptop policy would catch. Nobody outside that one conversation ever knew the screenshot existed, and no one on the security team had a reason to look for it.

Why does a free screenshot tool end up holding this much of your data?

Multiply that one click by every dashboard, ticket and internal message screenshotted over the years. A picture-sharing tool quietly becomes a second, unmanaged copy of whatever sensitive data passed through it. Nobody signed off on that copy existing. Nobody classified what was in it. It sat there, fully readable to a search engine let alone an attacker, until someone else's server vulnerability turned it into a breach notice in your inbox.

MIND's classification isn't limited to documents and spreadsheets. It reads content and context in images too, so a screenshot of a customer record or an internal system carries the same weight as the file it came from. Discovery extends to the browser-based and SaaS tools employees reach for on their own, the ones that never make an approved-vendor list because nobody asked before installing them. Real-time prevention sits in the browser itself, so a screenshot headed toward an unsanctioned tool can get flagged or blocked before it becomes someone else's breach years down the line.

MIND applies the same scrutiny to the quiet, unapproved tools as it does the sanctioned ones. It's minding the corners of the stack that feel harmless until a breach notice arrives.

If your team can't say which screenshot and file-sharing tools already hold a copy of your sensitive data, this is the moment to find out, before another vendor's breach notice makes the discovery for you. See how MIND discovers and classifies content across the tools employees actually use, whether IT approved them or not.

Tell us what’s on your mind. Get a live demo or just reach out to us.