ShinyHunters exploit Anodot incident to target Vimeo


ShinyHunters exploit Anodot incident to target Vimeo

Pierluigi Paganini
April 29, 2026

The video platform Vimeo confirmed a security breach via Anodot that exposed metadata, video titles, and some user emails.

Vimeo said some user data was accessed after a breach at Anodot. Anodot is a company that provides AI-driven data analytics and anomaly detection tools.

Most of the exposed information includes technical data, video titles, and metadata, while some customer email addresses were also affected. Vimeo says the incident did not expose user-uploaded videos, login credentials, or payment card data, and its platform continues to operate normally without disruption.

Vimeo noted the incident came from a third-party breach.

“Vimeo is aware of a security incident affecting Anodot, a third-party analytics vendor used by Vimeo and many other companies.” reads the notice published by Vimeo. “We have identified that, as a result of the Anodot breach, an unauthorized actor accessed certain Vimeo user and customer data. Our initial findings suggest that the databases accessed primarily contain technical data, video titles and metadata, and, in some cases, customer email addresses.”

In response to the incident, the company disabled all Anodot credentials and removed its integration with the service to stop further access. Vimeo notified law enforcement and is still investigating the incident with the help of external security experts.

Hackers from the extortion group ShinyHunters claimed the Vimeo breach and threaten to leak stolen data by April 30 if the company refuses to pay a ransom. They also warn Vimeo about possible “digital problems” if demands go unmet.

“Your Snowflake and Bigquery instances data was compromised thanks to Anodot.com. Pay or Leak.” reads the announcement published by ShinyHunters on its Tor data leak site. “This is a final warning to reach out by 30 Apr 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline.”

The attackers say they accessed data from Vimeo’s Snowflake and BigQuery environments. They also list the company on their leak site as part of their pressure campaign against the organization.

Attackers linked to the ShinyHunters group stole authentication tokens from Anodot and used them to access customer cloud environments, mainly Snowflake, to extract data from several organizations. The group now tries to monetize the breach through extortion and leak threats.

They also claim they took more than 78.6 million records from game studio Rockstar Games, though they have not confirmed the exact amount of data taken from Vimeo.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ShinyHunters)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Strike action is planned for 3 and 4 March, and 7-17 March 2026. Discussions with UNISON are ongoing.

We have made a clear and constructive offer to establish a union recognition agreement, following the standard process led by Acas. As part of our offer, a final agreement on recognition would be subject to a whole-staff ballot. This is to ensure all staff have a say in this important decision.

Regarding pay, we cannot offer any uplift for the financial year 2025/2026 as this would put our service delivery at unacceptable risk and is not sustainable. We have made our tight financial situation clear to UNISON at every stage of our negotiations.

Our clients’ wellbeing continues to be our priority

While we respect the right of union members to take lawful industrial action, our focus remains on maintaining safe, continuous support for the people who rely on our services every day.

We are working with our teams to put our updated business continuity plans into action. Team managers and senior leaders are supporting colleagues, and despite strike action, services are continuing with minimal disruption. 

We remain committed to resolving this dispute and we are working with UNISON, via Acas, to see if we can resolve our differences.

This is not without its challenges, particularly at this time of year, and we are grateful to our hundreds of colleagues and clients for their understanding and support. 

If people have questions or concerns, they can contact us on 0117 909 6630 or email reception@second-step.co.uk. You can also visit our Answers to key questions about the strike page for more information.

For media queries, please contact PR & Communications Manager Jane Edmonds on 07841777401 or email jane.edmonds@second-step.co.uk. For out-of-hours queries, please call 07846377292.



Source link