TL;DR: ShinyHunters breached Vimeo in April 2026, not by hacking Vimeo directly, but by compromising Anodot, a third-party analytics vendor. Stolen Anodot authentication tokens gave attackers access to Vimeo's Snowflake and Google BigQuery instances. The result: 119,200 users had their email addresses exposed, along with video metadata and technical data. After Vimeo refused to pay, ShinyHunters dumped a 106 GB archive on its dark web leak site. The same Anodot compromise also hit Rockstar Games, Zara (Inditex), and reportedly Udemy.
Your Vendor's Vendor Got Hacked
Vimeo did not get phished. Its employees did not click a bad link. Nobody fell for a fake login page. Instead, ShinyHunters broke into Anodot, a data anomaly detection company that Vimeo used for analytics, and stole authentication tokens that connected Anodot to Vimeo's cloud data warehouses [1][2].
Those tokens unlocked Vimeo's Snowflake and Google BigQuery instances. ShinyHunters did not need a Vimeo password. It did not need access to Vimeo's internal network. The tokens from a third-party integration were enough to reach in and pull data out [3].
This is the supply chain attack pattern that keeps repeating in 2026: attackers do not bother going after their real target. They find the weakest vendor in the chain and use that vendor's access as a key.
What Was Exposed
Have I Been Pwned added the leaked data on May 5, 2026, confirming 119,200 unique email addresses in the breach [4].
According to Vimeo's disclosure, the compromised data includes [1][2]:
- Email addresses of users and customers
- Names in some cases
- Video titles and metadata
- Technical data related to platform usage
Vimeo says no video content, login credentials, or payment card information was accessed. That is genuinely good news, but email addresses tied to a video platform still tell attackers what content you watch, what you create, and what organizations you belong to.
After its ransom deadline passed on April 30, ShinyHunters made good on its threat and published a 106 GB archive of stolen documents to its dark web leak site [4].
One Vendor, Four Victims
Vimeo is not the only company that got burned by the Anodot compromise. ShinyHunters' own leak site lists three organizations hit through the same vector [3][5]:
- Vimeo: 119,200 users, 106 GB leaked
- Rockstar Games: 78.6 million internal analytics records
- Zara (Inditex): breach claimed, scope not fully confirmed
Reports also link a Udemy data breach to the same Anodot compromise, though details remain thinner [5].
The pattern is identical every time: compromised Anodot credentials give access to the target's cloud data warehouses. Snowflake, BigQuery, whatever the customer was running: the Anodot tokens opened the door. One vendor breach, four corporate victims, hundreds of millions of records.
ShinyHunters' Supply Chain Playbook
ShinyHunters is running two parallel campaigns right now. The first, the Salesforce vishing spree, targets companies through phone calls to employees, tricking them into authorizing malicious Salesforce connected apps. That campaign has hit Cushman & Wakefield, Instructure, ADT, and 30+ others.
The second, the Anodot supply chain attack, is quieter but arguably worse. No social engineering required. No employee had to be tricked. ShinyHunters just found a vendor with access and took its keys.
Both campaigns exploit the same basic reality: modern companies give dozens of third-party tools deep access to their data, and any one of those tools can become an entry point.
Vimeo's Response
Vimeo disclosed the breach on April 28, 2026. The company said "the attack didn't cause any disruptions" and that "Vimeo user and customer login credentials are secure" [1].
The company took immediate steps [1][2]:
- Disabled all Anodot credentials
- Removed the Anodot integration entirely
- Engaged third-party cybersecurity experts
- Notified law enforcement
That response is reasonable. The problem is it came after the data was already gone. By the time Vimeo realized Anodot was compromised, ShinyHunters had already exfiltrated the data through the analytics vendor's own API connections.
What You Should Do
If you have a Vimeo account, whether as a creator or a viewer, take these steps:
- Change your password anyway. Vimeo says credentials were not exposed, but treat any breach as reason to rotate.
- Watch for phishing. Your email address is now in a leaked dataset. Expect more targeted spam and scam emails. Anything referencing Vimeo, your videos, or your account should be verified directly through Vimeo's website, not through links in emails.
- Check Have I Been Pwned. Go to haveibeenpwned.com and search your email to confirm whether it appeared in this breach.
- Enable two-factor authentication. If you have not already, turn on 2FA on your Vimeo account. Even if this breach did not include passwords, the next one might.
The Bigger Problem
Vimeo did not make a security mistake in the traditional sense. It used a legitimate analytics vendor, connected it through standard cloud integrations, and had no reason to suspect Anodot's credentials would be stolen. This is the nightmare scenario that security teams warn about but rarely prepare for: the breach that comes not from your perimeter, but from your tooling.
Every SaaS company connects to dozens of vendors through OAuth tokens, API keys, and cloud credentials. Each connection is a potential entry point. When one vendor gets compromised, every customer becomes a target, and the customer has no visibility into the vendor's security posture until it is too late.
ShinyHunters has figured this out. The question is whether the rest of the industry will catch up before the next Anodot happens.
Sources
- BleepingComputer: Vimeo data breach exposes personal information of 119,000 people (May 2026)
- SecurityWeek: Vimeo Confirms User and Customer Data Breach (April 28, 2026)
- CyberInsider: Vimeo suffers 3rd-party breach exposing user data, hackers threaten leak (April 2026)
- TechNadu: Almost 120,000 Vimeo accounts exposed in ShinyHunters data breach (May 2026)
- Security Affairs: ShinyHunters exploit Anodot incident to target Vimeo (April 2026)