ShinyHunters exploit Anodot incident to target Vimeo

ShinyHunters exploit Anodot incident to target Vimeo

ShinyHunters exploit Anodot incident to target Vimeo

https://securityaffairs.com/191448/security/shinyhunters-exploit-anodot-incident-to-target-vimeo.html

Publish Date: 2026-04-29 03:30:00

Source Domain: securityaffairs.com

ShinyHunters exploit Anodot incident to target Vimeo

Pierluigi Paganini
April 29, 2026

The video platform Vimeo confirmed a security breach via Anodot that exposed metadata, video titles, and some user emails.

Vimeo said some user data was accessed after a breach at Anodot. Anodot is a company that provides AI-driven data analytics and anomaly detection tools.

Most of the exposed information includes technical data, video titles, and metadata, while some customer email addresses were also affected. Vimeo says the incident did not expose user-uploaded videos, login credentials, or payment card data, and its platform continues to operate normally without disruption.

Vimeo noted the incident came from a third-party breach.

“Vimeo is aware of a security incident affecting Anodot, a third-party analytics vendor used by Vimeo and many other companies.” reads the notice published by Vimeo. “We have identified that, as a result of the Anodot breach, an unauthorized actor accessed certain Vimeo user and customer data. Our initial findings suggest that the databases accessed primarily contain technical data, video titles and metadata, and, in some cases, customer email addresses.”

In response to the incident, the company disabled all Anodot credentials and removed its integration with the service to stop further access. Vimeo notified law enforcement and is still investigating the incident with the help of external security experts.

Hackers from the extortion group ShinyHunters claimed the Vimeo breach and threaten to leak stolen data by April 30 if the company refuses to pay a ransom. They also warn Vimeo about possible “digital problems” if demands go unmet.

“Your Snowflake and Bigquery instances data was compromised thanks to Anodot.com. Pay or Leak.” reads the announcement published by ShinyHunters on its Tor data leak site. “This is a final warning to reach…

Source