← Blog

Vimeo: Anodot Token Theft Exposes Customer Email Metadata

Share on X

Vimeo disclosed that the Anodot incident let an unauthorized actor read databases holding chiefly technical metadata, video titles, and—in some cases—customer email addresses, while ruling out uploaded video files, passwords, and cards in its first wave of messaging. Coverage linked the case to the same ShinyHunters / Snowflake-BigQuery integrator saga affecting other brands.

Canonical record: Vimeo / Anodot 2026 on BreachHistory.

Sources: BleepingComputer, Vimeo

May 5 update: BleepingComputer reported that Have I Been Pwned analyzed the leaked Vimeo dataset and counted 119,200 exposed people, primarily email addresses and in some cases names. Vimeo continued to state that valid login credentials, payment card information, and video content were not included.