Vimeo Data Breach Exposes Email Addresses of 119,000 Users

Video hosting giant Vimeo has confirmed a data breach that exposed approximately 119,200 unique user email addresses, tracing the incident not to its own infrastructure, but to Anodot, a third-party AI-powered analytics vendor integrated into its platform.

The breach came to light after the notorious ShinyHunters extortion group added Vimeo to its “pay or leak” portal in April 2026, and subsequently published hundreds of gigabytes of stolen data after no ransom payment was made.

The stolen data primarily consisted of video titles, technical metadata, and, in some instances, customer email addresses paired with names.

Vimeo was explicit in its official disclosure, published on April 27, 2026, that the breach does not include Vimeo video content, valid user login credentials, or payment card information.

The incident was added to the Have I Been Pwned (HIBP) breach notification service on May 5, 2026, formally flagging 119,200 affected accounts.

ShinyHunters Expands SaaS Supply Chain Targeting

The ShinyHunters group is no stranger to high-profile breaches. Known for systematically targeting software-as-a-service platforms, the group has increasingly shifted its focus toward third-party vendors and analytics providers as an indirect pathway into enterprise environments.

Google Threat Intelligence has published a report directly linking the Anodot compromise to ShinyHunters’ broader SaaS data theft campaign, highlighting how a single vendor breach can cascade into exposure for multiple enterprise clients simultaneously.

Anodot is an AI-powered business analytics and anomaly detection platform used by Vimeo and a wide range of enterprise customers.

Because such platforms ingest and process data from multiple organizations, they represent high-value targets.

A successful compromise of an analytics vendor can yield access to data from dozens or hundreds of clients, amplifying the impact of a single intrusion well beyond what a direct attack on any one company would achieve.

By targeting the supply chain rather than Vimeo’s core systems directly, ShinyHunters effectively bypassed the stronger security controls that Vimeo had in place for its primary infrastructure.

This strategy reflects a broader and growing trend in the threat landscape, where adversaries look for the weakest link in an interconnected ecosystem rather than mounting a frontal assault on a hardened target.

Upon discovering the incident, Vimeo moved quickly to contain the damage. The company immediately disabled all Anodot credentials, severed the Anodot integration from its systems entirely, and brought in third-party cybersecurity experts to assist with the forensic investigation.

Law enforcement has also been notified, and Vimeo stated that its investigation remains ongoing, with further updates to be provided as new information emerges.

The databases accessed through the Anodot breach contained technical data and video metadata, video titles, and customer email addresses, in some cases accompanied by account holder names.

Vimeo confirmed that user and customer login credentials remain secure, and that no disruption to its platform or services occurred as a result of the incident. Critically, no payment card data was accessed or exposed.

This incident serves as a sharp reminder of the expanding attack surface created by modern SaaS ecosystems.

Even when a company’s core infrastructure is well-hardened, integrations with external analytics, monitoring, or data management services can introduce significant and often underestimated risk.

Third-party vendors frequently hold sensitive data from multiple enterprise clients, yet they may not always be subject to the same rigorous security standards as the organizations they serve.

Security teams across the industry should treat this breach as a call to action. Enforcing strict data minimization policies with vendors, conducting regular third-party security assessments, limiting the scope of data shared with analytics integrations, and maintaining the ability to rapidly revoke external access are now baseline requirements rather than best practices.

As ShinyHunters and similar groups continue to refine their supply chain targeting strategies, organizations that have not yet audited their third-party integrations are operating with an invisible but very real risk exposure.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories