Skip to main content
Back to overview
Medium

Vimeo Confirms User and Customer Data Breach via Third-Party Vendor Anodot

Video hosting platform Vimeo confirmed a data breach affecting user and customer data, stemming from an attack on its third-party analytics provider, Anodot.

Key points

  • Data breach originated from a compromised third-party analytics vendor, Anodot.
  • ShinyHunters group claimed responsibility.
  • Customer email addresses, technical data, and video metadata were exposed.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Partner actor · Confidentiality impact

Possible third-party involvement

03

Potential impact

Potential data exposure

Confidentiality

Published
Apr 28, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible third-party involvement

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: supplier or third-party involvement

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

VimeoData DisclosureVimeo Confirms User and CustomerThird-Party Vendor Anodot VideoVimeoAnodot. The ShinyHuntersSnowflake and BigQueryAnodot. ShinyHuntersCustomer

Quick context

Questions about this signal

What happened in this signal?

Video hosting platform Vimeo confirmed a data breach affecting user and customer data, stemming from an attack on its third-party analytics provider, Anodot. The ShinyHunters group claimed responsibility, stating they accessed Vimeo's Snowflake and BigQuery cloud environments using stolen authentication tokens. The breach exposed customer email addresses, technical data, and video metadata, but Vimeo confirmed that video content, login credentials, or payment data were not compromised.

When was this signal reported?

Shadow Tier lists Apr 28, 2026 as the signal date.

Which organization is connected to this signal?

Vimeo is the organization connected to this public signal.

Explore Vimeo