Hackers have stolen a massive trove of user data from PornHub, one of the world's largest adult websites, exposing millions of users to potential extortion and privacy risks. The breach, attributed to the ShinyHunters group, reportedly involved the theft of over 200 million records, including email addresses, usernames, and encrypted passwords. The attackers are believed to be leveraging this sensitive information for extortion purposes, targeting users with threats of exposure unless a ransom is paid. The incident has reignited concerns about the security of high-traffic adult platforms and the adequacy of their encryption and third-party risk management practices.
Security experts warn that the breach could lead to widespread credential stuffing and phishing campaigns, given the scale and sensitivity of the data involved. Investigations are ongoing, and affected users are advised to change their passwords and remain vigilant for suspicious communications. The breach underscores the persistent threat posed by organized cybercriminal groups and highlights the need for robust security measures and rapid incident response in the face of large-scale data compromises.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
A cybersecurity weekly recap consolidated major incidents from the period, including the Pornhub breach, Cisco zero-days, ransomware developments, and multiple exploited vulnerabilities. This reference did not clearly introduce additional discrete dated events beyond those already separately described.
Reporting indicated that Chinese fraudsters were using AI-generated images to trick ecommerce platforms into issuing refunds. The tactic reflects growing criminal use of generative AI in online fraud operations.
The Haotian AI application was reported as being actively promoted to fraudsters in Southeast Asia. It enables realistic live-video face swaps that can be used to support scams and impersonation.
Two cybersecurity professionals from Sygnia Consulting and DigitalMint pleaded guilty to carrying out ransomware attacks. One of the attacks reportedly extracted $1 million from a Florida medical device company.
Venezuela's state oil company PDVSA suffered a cyberattack that disrupted operations. The company blamed the United States after a tanker seizure, though reporting suggested the impact may have been greater than publicly acknowledged.
The ShinyHunters group reportedly stole more than 200 million PornHub user records, likely via a third-party analytics provider, and began extorting the company. Separate reporting also described a large-scale credential theft affecting an adult platform and highlighted the Pornhub Premium breach as a major incident.
Cisco revealed an unpatched zero-day vulnerability affecting its Secure Email Gateway and Web Manager products. The company said the flaw had been exploited since November by a suspected Chinese state-sponsored group and provided mitigations while no patch was yet available.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.