2026 Vimeo — Anodot / Snowflake-token chain; 119,200 emails/names in HIBP after ShinyHunters leak
Data compromised
Email addresses, names for some users, technical analytics metadata, and video titles/metadata; no valid login credentials, payment cards, or video content per Vimeo
Technical writeup
In late April 2026, Vimeo confirmed unauthorized access to some customer and user data stemming from the broader Anodot incident, where attackers stole SaaS integration tokens and pivoted into client cloud analytics environments—coverage from BleepingComputer tied the narrative to the same ShinyHunters extortion wave affecting other Snowflake/BigQuery-oriented victims. Vimeo’s blog post described databases accessed as primarily technical in nature—video titles and metadata—with customer email addresses in subsets, explicitly excluding uploaded video content, account passwords, and payment cards; the firm disabled Anodot credentials and removed integrations while investigating with external responders and law enforcement. ShinyHunters listed Vimeo with pay-or-leak deadlines; treat actor inventory claims as partially unverified versus the company’s confirmed categories. On May 5, 2026, BleepingComputer reported that Have I Been Pwned analyzed the leaked data and found 119,200 exposed people, primarily email addresses and in some cases names. BleepingComputer also reported that ShinyHunters leaked a 106GB archive after failed extortion, while Vimeo continued to state that video content, valid login credentials, and payment card information were not included.
Root cause
Third-party (Anodot) token theft enabling downstream cloud data-store access (supply-chain / integrator breach)
References
- https://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/
- https://vimeo.com/blog/post/anodot-third-party-security-incident
- https://www.bleepingcomputer.com/news/security/snowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach/
- https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/