What's in Your Screenshots Folder? The Gyazo Breach Says: Everything
The Gyazo breach exposed text read out of people's screenshots. Here's how to audit your own screenshots, stop needless uploads and store the rest safely.
Published 2026-09-23
The short version
- Screenshot service Gyazo reported a breach affecting 23.62 million user records, disclosed on 21 September 2026.
- The stolen data included text the service had extracted from screenshots with OCR — so what was written inside the images was in the haul.
- Screenshots quietly collect invoices, password resets, ID documents and client details, then sync to the cloud without a second thought.
- An hour spent auditing, deleting and switching off auto-upload removes most of the risk.
What happened in the Gyazo breach?
Gyazo is an image and screenshot-sharing service run by the Japanese company Helpfeel. On 21 September 2026, it was reported that an attacker had exploited a flaw in Gyazo's image upload server that allowed arbitrary commands to run. The access happened on 11 September and was detected and blocked on 12 September.
The numbers are large: 23.62 million user records, covering email addresses, password hashes, IP addresses, image IDs and — in some cases — embedded location data. On top of that, around 490 million image metadata records were taken, mostly for images uploaded before January 2019. The attacker also took a list of which images were marked private, and Helpfeel has said it cannot rule out that private images were viewed.
Helpfeel reported the incident to Japan's Personal Information Protection Commission on 15 September, took the platform offline and asked all users to change their passwords.
Why does OCR make a screenshot breach worse?
One item in that list deserves more attention than it got: OCR-extracted text.
OCR, or optical character recognition, is software that reads the words inside an image. Many services run it automatically so you can search your screenshots by what's written in them. It's genuinely handy. It also means the service has already turned your pictures into plain, searchable text before anyone attacks it.
So when that text is stolen, an attacker doesn't need to look through millions of images one at a time. They can search. For "password". For "invoice". For a bank's name, a street address or a client's surname.
That changes how you should think about screenshots. They aren't just pictures. They're documents — often the most sensitive documents you have, captured precisely because you needed to keep something important.
What's actually in your screenshots folder?
Open your phone's photo library and scroll to the screenshots album. Most people are surprised by what's there. Common finds include:
A password reset email or a one-time code, captured "just in case". An invoice or receipt showing your address and the last digits of a card. A photo of your driver licence, passport or Medicare card, taken for a sign-up form. A banking screen with a balance, account number or BSB. A booking confirmation with your travel dates — which also tells someone when your home is empty. Chat messages with other people's names and phone numbers. Work material: a client's details, a spreadsheet, a slide you weren't meant to share.
Every one of those is fine sitting on a locked phone in your pocket. The risk comes when the same image is quietly copied to a service you've forgotten about, where it sits for years and gets processed in ways you never considered.
How to audit and clean up your screenshots
Set aside an hour. This is dull work, but it's one of the highest-value privacy clean-ups you can do, and you only need to do the big one once.
- Open your screenshots album and sort or scroll by date. Start with the oldest — they're the ones you're least likely to need.
- Delete anything containing a password, a reset link, a one-time code or a recovery key. If it's a recovery key you still need, move it into a password manager or write it down and store it safely, then delete the image.
- Find every image of an identity document — licence, passport, Medicare card, birth certificate — and delete it unless you have a clear, current reason to keep it.
- Delete old invoices, bank screens and booking confirmations. If you need records, save the original PDF somewhere encrypted instead of keeping a screenshot.
- Empty the "Recently deleted" or bin folder on your phone. Most phones keep deleted photos for around 30 days.
- Repeat the same clean-up in any cloud photo backup you use, because deleting on the phone doesn't always remove every copy in the cloud.
Turn off auto-upload you don't need
The quieter problem is where your screenshots go automatically. Many people have two or three services uploading every image they take: the phone's own photo backup, a cloud drive app, a screenshot-sharing tool installed years ago for work, and sometimes a messaging app that saves to the cloud.
Go through your phone's settings and the settings of each photo or file app, and ask a simple question: do I actually use this backup? If not, switch off its automatic upload, then sign in on the web and delete what it already holds. If the service is one you've stopped using entirely, delete the account — JustDeleteMe is a free directory of account-deletion links and instructions for hundreds of services.
If you do use a cloud backup, check whether it offers a locked or hidden folder, and whether screenshots can be excluded from automatic backup. On a computer, check whether a screenshot tool is set to upload captures by default; some share a link the moment you take the shot.
One more setting while you're there: turn off location tagging in your camera app. Photos can carry the exact spot they were taken, and Gyazo's breach included embedded location data in some cases.
Where should sensitive images live instead?
Some images you genuinely need to keep: a scan of your passport for travel, a copy of a contract, proof of a payment. For those, the safest home is storage that's encrypted before it leaves your device, so the provider can't read the contents — and can't run OCR on them either.
That's the important difference. With ordinary cloud storage, the provider holds the keys, which is what makes features like searchable text possible. With end-to-end encrypted storage, only you hold the keys. If the provider is breached, the attacker gets scrambled data. We maintain a separate site, NoSpyDrive, that looks at the private cloud storage options that meet that bar, if you're weighing up where to move your files.
If you'd rather not use any cloud service for the most sensitive items, a free, open-source tool such as VeraCrypt can create an encrypted container on your own computer or USB drive.
If you ever used Gyazo, do this now
Change your Gyazo password, as Helpfeel has asked. More importantly, if you used the same password anywhere else, change it there too — password hashes can sometimes be cracked, and reused passwords are how one breach becomes five. Have I Been Pwned is a free service that tells you which known breaches your email address has appeared in; it's worth checking regularly.
Then think about what you uploaded. If there were screenshots of password resets, IDs or banking details, treat those details as potentially exposed: change the passwords, watch the accounts, and be sceptical of any call or email that seems to know a little too much about you.
Can you find out exactly what was taken?
Honestly, probably not in detail. Helpfeel has said it can't rule out that private images were viewed, and it isn't practical for any company to tell 23 million people which of their images were looked at.
In Australia, you can ask any organisation covered by the Privacy Act what personal information it holds about you, and complain to the Office of the Australian Information Commissioner (OAIC) if it doesn't respond properly. In the UK, the ICO handles complaints; in the EU, your national data protection authority. Gyazo reported this breach to Japan's regulator. Expect answers to be slow and general. A government agency is generally required to hand over the records it holds about you when you ask; the long tail of apps and services that quietly collected your images are under far less practical pressure, and most won't volunteer anything. It's a useful reminder that the most reliable protection is not having the sensitive image stored anywhere you don't control.
What to do this week
Open your screenshots album and delete the passwords, IDs and invoices. Empty the bin. Switch off auto-upload for any service you don't actively use, and delete the old accounts. Move the few images you genuinely need into encrypted storage.
Screenshots feel temporary. They aren't. The Gyazo breach is a reminder that whatever you capture can end up being read — by software first, and then possibly by someone you'd never choose to show it to.
Frequently asked questions
What data was stolen in the Gyazo breach?
Reported data includes email addresses, password hashes, IP addresses, image IDs, OCR-extracted text from images and, in some cases, embedded location data, plus about 490 million image metadata records. Helpfeel says it cannot rule out that private images were viewed.
Should I change my Gyazo password?
Yes. Helpfeel has asked all users to change their password, and you should also change it anywhere else you used the same one.
Are screenshots stored in the cloud private?
Only as private as the service storing them. If the provider can read your images — for example to make text searchable — a breach of that provider can expose what's in them. End-to-end encrypted storage avoids this because the provider can't read the contents.
Is it safe to keep a photo of my passport or driver licence on my phone?
It's safer not to. If you must keep one, store it in encrypted storage rather than your camera roll, and make sure it isn't being automatically copied to cloud services you don't need.
Ready to act on this?
We've reviewed the tools so you don't have to.