// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Gyazo

DISCLOSED 2026-09-18 · UNPATCHED CVE · 23,620,000 RECORDS EXPOSED

A vulnerability in the image sharing service Gyazo resulted in the exposure of 23.62 million user records and 490 million image records. The exposed data includes personally identifiable information (PII) and metadata. The breach was caused by a vulnerability in the service, but no further details on the attack vector or threat actor were provided.

The record

What we know

Disclosed
2026-09-18
Attack vector
Unpatched Cve
Sector
technology
Records exposed
23,620,000
Domain
gyazo.com
Data classes exposed
PIImetadata
Sources

Cited reporting

Similar vector · recent

Other unpatched cve breaches on file

This page is the permanent ColdRecon entry for the Gyazo disclosure. It updates if new public reporting emerges. All tracked breaches →

Gyazo just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →