← Vimeo

2026 Vimeo — Anodot / Snowflake-token chain; 119,200 emails/names in HIBP after ShinyHunters leak

2026 119.2K records affected Share on X

Data compromised

Email addresses, names for some users, technical analytics metadata, and video titles/metadata; no valid login credentials, payment cards, or video content per Vimeo

Technical writeup

In late April 2026, Vimeo confirmed unauthorized access to some customer and user data stemming from the broader Anodot incident, where attackers stole SaaS integration tokens and pivoted into client cloud analytics environments—coverage from BleepingComputer tied the narrative to the same ShinyHunters extortion wave affecting other Snowflake/BigQuery-oriented victims. Vimeo’s blog post described databases accessed as primarily technical in nature—video titles and metadata—with customer email addresses in subsets, explicitly excluding uploaded video content, account passwords, and payment cards; the firm disabled Anodot credentials and removed integrations while investigating with external responders and law enforcement. ShinyHunters listed Vimeo with pay-or-leak deadlines; treat actor inventory claims as partially unverified versus the company’s confirmed categories. On May 5, 2026, BleepingComputer reported that Have I Been Pwned analyzed the leaked data and found 119,200 exposed people, primarily email addresses and in some cases names. BleepingComputer also reported that ShinyHunters leaked a 106GB archive after failed extortion, while Vimeo continued to state that video content, valid login credentials, and payment card information were not included.

Root cause

Third-party (Anodot) token theft enabling downstream cloud data-store access (supply-chain / integrator breach)

References