Vimeo confirmed that attackers accessed customer and user data through a breach at third-party analytics provider Anodot, exposing about 119,000 unique email addresses and, in some cases, associated names. The stolen information also included technical operational data, video titles, and metadata, while Vimeo said video content, valid login credentials, payment card data, and core platform operations were not affected. The company said the incident did not disrupt service and that the compromise stemmed from vendor access rather than a direct intrusion into Vimeo’s own systems.
The ShinyHunters extortion group claimed responsibility, listed Vimeo on its leak site, and later published a 106GB archive after an alleged pay-or-leak demand failed. Multiple reports said the attackers may have abused Anodot authentication tokens to reach customer cloud environments, including alleged access to Snowflake and BigQuery data tied to Vimeo. Vimeo responded by revoking and disabling Anodot credentials, removing the integration, engaging external forensic experts, notifying law enforcement, and warning users that the exposed contact data could be used in follow-on phishing and social engineering attacks.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned reported that the breach exposed roughly 119,000 unique email addresses, with some associated names, and added about 119,200 affected accounts to its database. This quantified the scope of the exposed user data.
Later reporting said ShinyHunters released at least part of the stolen Vimeo dataset, including a 106GB archive, after extortion attempts failed. The leaked material was described as largely technical data, metadata, video titles, and some email addresses and names.
Multiple reports state that ShinyHunters added Vimeo to its pay-or-leak site in April 2026 after claiming to have stolen data via the Anodot-related compromise. The group threatened to leak the data if a ransom was not paid.
Reporting on the extortion campaign said ShinyHunters threatened to publish Vimeo data by April 30, 2026 if its ransom demand was not met. The group also claimed access to Vimeo-related cloud data through the Anodot compromise.
Following the disclosure, Vimeo said it disabled all Anodot credentials, removed the Anodot integration, engaged external security experts, and notified law enforcement. The company also said the incident caused no service disruption.
Vimeo disclosed that unauthorized access to certain user and customer data occurred through a breach involving third-party analytics vendor Anodot. The company said exposed data mainly included technical data, video titles, metadata, and some email addresses, while video content, valid credentials, and payment card data were not accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourceteiss.co.uk
Open sourceuk.pcmag.com
Open sourcetherecord.media
Open sourcevimeo.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.