ShinyHunters, a well-known hacking group, claimed responsibility for a breach at analytics provider Mixpanel, resulting in the exposure of historical analytics data related to Pornhub Premium users. The compromised data reportedly includes search, watch, and download activity, but does not contain passwords, payment information, or government IDs. Pornhub clarified that its own systems were not breached and that the affected data was legacy information from when the company used Mixpanel prior to 2021. The breach has raised concerns about the security of third-party vendors and the risks of retaining historical user data.
Following the breach, ShinyHunters began extorting Mixpanel customers, including Pornhub, threatening to publish the stolen data unless a ransom was paid. The group claims to possess over 200 million records tied to Pornhub Premium users. While Pornhub and Mixpanel have both launched investigations, Mixpanel disputes that the data originated from its recent November 2025 incident, suggesting the data may have been accessed through other means. Users are advised to remain vigilant for phishing attempts and to enable multi-factor authentication as a precaution.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Mixpanel publicly denied that the Pornhub data was stolen from its systems during the November 2025 smishing incident, arguing the data may instead have been accessed earlier through a legitimate Aylo employee account in 2023. The company said the affected account had since been secured.
Security researchers and outside verification efforts, including reports citing BreachForums posts and independent analysis, confirmed that at least some of the exposed Pornhub-related data appeared authentic.
Pornhub stated that the incident involved a third-party analytics provider rather than Pornhub's own infrastructure. It said no passwords, payment information, or government IDs were exposed and launched an internal investigation with outside experts and authorities.
ShinyHunters started threatening to publish the stolen analytics data unless ransoms were paid, targeting Pornhub and other Mixpanel customers. The campaign turned the data theft into an active extortion incident.
Following the Mixpanel incident, ShinyHunters claimed it had obtained 94GB of Pornhub Premium user analytics data, including more than 200 million records of search, watch-history, location, and timestamp information.
On November 8, 2025, Mixpanel was reportedly compromised through an SMS phishing or smishing attack. The intrusion allegedly exposed customer analytics data later tied to Pornhub Premium user activity.
Mixpanel said the affected Pornhub-related data was last legitimately accessed in 2023 by an employee account belonging to Pornhub's parent company, Aylo. This later became central to Mixpanel's dispute over how the data was obtained.
Pornhub said it stopped using Mixpanel in 2021, indicating the exposed analytics data was legacy information from that period or earlier.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.