Back to blog

Screenshot Tool Security for Small Business: What the Gyazo Breach Says About the Data Hiding in Your Images

The Gyazo breach exposed 23.6 million accounts and text read from old screenshots. What screenshot tool security means for a small business, and what to do now.

Think about the last ten screenshots your team took for work. One was probably an invoice. One was a login screen with an error on it. One might have been a bank portal, a customer's order, or a settings page with an API key sitting in the corner. Screenshot tool security is not something most small business owners have ever thought about, and this month's Gyazo breach is a good reason to start.

Gyazo is a popular free screenshot and screen-sharing tool. You press a shortcut, grab part of your screen, and it gives you a link to paste into an email or chat. Plenty of people installed it years ago and never thought about it again. On 21 September 2026, Help Net Security reported that attackers had broken into Gyazo's systems and taken 23.62 million user records, along with metadata for roughly 490 million images.

This article explains what was taken, why screenshots are a bigger data risk than they look, and what a small business with no IT person should do this week.

What Happened in the Gyazo Data Breach

Here are the facts as reported by Help Net Security (21 September 2026), BleepingComputer and The Hacker News.

  • When: Attackers got in on 11 September 2026. The company found the intrusion that evening and blocked access in the early hours of 12 September. It reported the incident to Japan's privacy regulator on 15 September.
  • How: Attackers used a flaw in Gyazo's image upload server to run their own commands on it.
  • User data taken (23.62 million records): names, email addresses, password hashes, user IDs, device IDs, login session IDs, X (Twitter) integration tokens, Google sign-in email addresses, profile details, subscription plans and billing status.
  • Image data taken (about 490 million records): mostly from images uploaded before January 2019. This includes image IDs, upload IP addresses, browser details, location data from photos, image titles, source URLs, hashed passphrases for private images, and the text the service had read out of the images.
  • Payment details: the company says no credit card numbers were exposed.

Two lines in that list deserve more attention than the headline number.

The first is "the text the service had read out of the images." Many screenshot tools run text recognition (OCR) on your uploads so you can search them later. That means the words inside your screenshots were stored as plain searchable text. Invoice numbers, customer names, email threads, whatever was on screen.

The second is the image IDs. Gyazo links were treated as private because the ID was too long to guess. Now attackers do not need to guess. The company has said it "cannot rule out the possibility that some private images may have been viewed."

Why Screenshots Are a Bigger Data Risk Than They Look

Most businesses think about data risk in terms of systems: the accounting software, the email account, the CRM. Screenshots slip past that thinking because they feel temporary. You take one, send it, and forget it.

But a screenshot is a copy of whatever was on your screen, stored somewhere else, often forever.

Screenshots capture things nobody meant to share

When someone grabs a screenshot to show a problem, they rarely crop carefully. The error message is in the middle, but the browser tabs, the bookmarks bar, the open email in the background and the customer record on the side all come along too.

Common things that end up in business screenshots:

  • Invoices and quotes with customer names, addresses and amounts
  • Bank and payment portal screens
  • Admin settings pages, sometimes with keys or tokens visible
  • Customer orders, support tickets and chat conversations
  • Staff rosters, pay information and internal spreadsheets
  • Login pages, including the username and sometimes a password hint

None of this is dramatic on its own. Stored in one place with the text already searchable, it is a very useful pile for a scammer.

"Unlisted" is not the same as private

A lot of free sharing tools work on the same idea: the link is long and random, so only people you send it to can open it. That works well right up until someone gets hold of the list of links. The Gyazo breach is exactly that situation.

The same idea sits behind "anyone with the link" sharing in Google Drive, OneDrive, Dropbox and many design and file tools. It is convenient, and it is often fine. It is just worth knowing that the protection is secrecy of the link, not a lock.

Old uploads never really go away

Most of the image data in this breach was from before 2019. Think about what your business looked like in 2018. Different staff, different suppliers, maybe a different business name. Screenshots from that time were still sitting on a server, with their text readable, seven years later.

You can clean up how you work today, but the uploads from years ago are still wherever you left them.

The Password Problem Behind Every Breach Like This

Gyazo stored passwords as hashes, which is standard practice. A hash is a scrambled version of a password that cannot simply be read back. The company has not said which method it used, and weak or older methods can be cracked for common passwords.

That is why the company's advice was to change your Gyazo password and also change it anywhere else you used the same or a similar one.

For a small business, password reuse is where a breach at a free screenshot tool turns into a problem with your email or your bank. It usually plays out like this:

  1. A staff member signs up for a free tool using their work email and a password they use elsewhere.
  2. That tool is breached and the email and password hash are taken.
  3. The password is cracked, or it was weak enough to guess.
  4. Attackers try the same email and password on Microsoft 365, Google Workspace, Xero, MYOB, Shopify and other common business logins.

If multi-factor authentication (MFA) is turned on, step four usually fails. If it is not, the attacker is in, and nothing about it looks unusual because they logged in with a real password.

There is one more detail that matters here. Some Gyazo accounts used Google sign-in rather than a password. The breach included the Google email addresses linked to those accounts. That does not give anyone access to the Google account itself, but it does confirm to a scammer that the address is real and in use, which makes it a better target for phishing.

What Small Business Owners Should Do This Week

You do not need a security team for this. Most of the work is finding out what you use and tidying up what you find.

1. Ask your team which screenshot and sharing tools they use

Send one message to your team: "Which apps do you use for screenshots, screen recordings or sharing images?" You will likely get a mix of answers. Gyazo, Lightshot, Snagit, Loom, CleanShot, ShareX, Droplr, and the built-in Windows and Mac tools are all common. Some of these run as browser extensions, which means they can see every page, not just the ones you capture.

The built-in tools (Snipping Tool on Windows, the Screenshot app on Mac) save to the local computer by default. That is a very different risk from a tool that uploads every capture to someone else's server. Knowing which is which is the whole point of this step.

2. If anyone used Gyazo, change the password everywhere it was reused

Anyone who had a Gyazo account should:

  • Change their Gyazo password, or delete the account if they no longer use it
  • Change the password on any other account that used the same or a similar password, starting with work email
  • Disconnect Gyazo from their X account if it was linked, since integration tokens were taken

Make it clear this is about reused passwords, not blame. The fix is a password manager, not a lecture.

3. Make sure MFA is on for the accounts that matter most

If you only do one thing from this article, do this. MFA is what stops a stolen password from becoming a stolen account. If you run Microsoft 365, the strongest option is a passkey, and Microsoft switched those on by default from 1 September. Check it is turned on for:

  • Email (Microsoft 365 or Google Workspace)
  • Banking and payment platforms
  • Accounting software
  • Your website, domain registrar and online store
  • Any admin account for anything

4. Clean out old uploads you no longer need

If a tool you use keeps a history of your uploads, log in and look at it. Delete anything with customer details, financial information or internal screens that has no reason to still exist. Do the same for old "anyone with the link" shares in Google Drive, OneDrive or Dropbox.

This will not undo what was taken from Gyazo. It will shrink the pile that is sitting around for the next breach.

5. Set a simple rule for screenshots going forward

You do not need a policy document. A few plain habits cover most of the risk:

  • Use the built-in screenshot tool by default and paste images directly into email or chat, rather than uploading to a sharing site
  • Crop to the part that matters before sending
  • Never screenshot passwords, banking screens or payment details to share them
  • If a tool must be used for sharing, use one the business has chosen and knows about, with a work account that can be closed when someone leaves

6. Watch for breach alerts on your team's work emails

Breaches like this are often added to Have I Been Pwned (HIBP), a free and widely trusted service that tracks which email addresses appear in known breaches. You can check individual addresses there, or set up alerts for your domain. It is the easiest way to find out that a work email was caught up in a breach at a tool you did not even know your team used.

The Real Lesson: You Cannot Protect Data You Do Not Know You Have

It would be easy to read this as "Gyazo bad, stop using Gyazo." That misses the point. Gyazo will fix its servers. Another free tool will have a breach next month.

The real issue for a small business is simpler and harder at the same time. Your business data lives in more places than you think. It lives in the tools you chose, and it lives in the tools your team picked up on their own to get a job done faster. Every one of those tools holds a copy of something. When one of them is breached, you can only respond well if you know it was in use and which email addresses were attached to it.

Bigger companies have an IT team to keep that list. A business with five or ten people usually has an old spreadsheet, or nothing at all. That is not carelessness. Nobody has time to be the IT department on top of their real job.

Where Vera Fits

This is the gap Vera was built for. Vera is an IT visibility dashboard for small businesses with 1 to 20 staff, built by someone who spends his day job looking after IT for businesses and kept seeing the smallest ones fall through the cracks.

For a situation like the Gyazo breach, a few parts of Vera help directly:

  • Breach monitoring: Vera checks your team's email addresses against Have I Been Pwned and shows you who has turned up in a known breach, so you are not relying on someone reading the news.
  • Software and licences: one list of the tools your business uses, who uses them and what they cost. When a breach hits the news, you can check in seconds whether it affects you.
  • Team directory: a clear record of who works for you, so the "change your password" message reaches everyone.
  • IT tasks: turn the checklist above into tasks with owners, so "turn on MFA for the accounting login" actually gets done instead of living in your head.

It will not stop a vendor from being hacked. Nothing you buy will. What it gives you is the thing that makes a breach like this a 20-minute job instead of a week of guessing: knowing what you use and who is exposed.

Screenshot Tool Security Starts With Knowing What You Use

The Gyazo breach is a useful reminder that screenshot tool security is really data security. The screenshots your team took years ago held invoices, customer details and internal screens, and the text inside them was stored and searchable. Now a large archive of that data is in the wrong hands.

You cannot undo that. You can find out which tools your team uses, change reused passwords, turn on MFA, clean up old uploads and keep an eye on breach alerts from here on. None of it takes long, and all of it is easier once you have one clear picture of your IT.

If you want that picture without building another spreadsheet, take a look at Vera at verait.io.