Vimeo has confirmed a data breach affecting platform users and clients, but the intrusion did not begin inside Vimeo. According to the company's own statement, the incident occurred at Anodot, a third-party analytics provider integrated with Vimeo systems. Vimeo says attackers reached databases containing technical data, video titles, metadata and, in some cases, client email addresses, while insisting that no video content, valid login credentials or payment card data was obtained. The extortion group ShinyHunters has claimed responsibility. Figures for the number of affected users vary by source: MetaCompliance puts the toll at "more than 119,000 users," while Vimeo's own public statement, as relayed by DigitalShield, gives no count at all. Treat 119,000 as a single-source figure, not a confirmed one.
What Happened
The timeline itself is one of the places sources diverge. MetaCompliance dates Vimeo's disclosure to April 2026 and describes attackers compromising Anodot's environment and using stolen authentication tokens to reach connected cloud resources. DigitalShield published its account of the confirmation on 2 May 2026. Neither source establishes the date of initial compromise, the duration of attacker access, or when Vimeo detected it. That gap matters: in the comparable Ernst & Young case, the window between intrusion and detection ran roughly a month (attacker access from 28 March to 12 April, unusual activity detected 23 April, per BleepingComputer and SecurityWeek). Assume a similar lag here until Vimeo says otherwise.
Vimeo's response, quoted directly in its statement, was containment-first: "Upon learning of the incident, we immediately deactivated all Anodot credentials, removed the Anodot integration with Vimeo systems, and hired external security experts to assist in the investigation. We have also notified law enforcement authorities." The company says the incident caused no disruption to its systems or service, and that "the access credentials of Vimeo users and clients are secure." The investigation is described as ongoing.
MetaCompliance reports that ShinyHunters attempted to extort Vimeo by threatening to publish the stolen data. Vimeo's public statements do not address extortion, payment or leak-site listing, and no source here confirms whether data was ultimately published.
What Was Taken
Vimeo's characterisation is consistent across both sources that cover the incident. The exposed data comprises:
- Customer and client email addresses (in some cases, per Vimeo)
- Video titles
- Metadata associated with hosted video
- Technical and analytics data of the kind an observability vendor would ingest
Explicitly excluded by Vimeo: video content itself, valid user login credentials, passwords, and payment card information. Note that this is the victim's own scoping of an investigation it describes as still open. Breach scope statements are provisional by nature, and the incidents.biz response checklist makes the operational point directly: track whether the organisation's explanation of what was affected changes over time.
The 119,000-plus user figure appears only in MetaCompliance's write-up and is not corroborated by Vimeo's statement or by any outlet-tier reporting in this set. It should be attributed, not asserted.
Even on Vimeo's own accounting, this is not a nothing-burger. Email addresses paired with video titles and account metadata are a phishing kit in raw form: an attacker knows who you are, what you published, and can reference real content in a lure. For enterprise Vimeo customers, unreleased or internal video titles can themselves be commercially sensitive.
Why It Matters
Vimeo is the smaller entry in a pattern that has become ShinyHunters' operating model through 2025 and 2026. The group did not attack Vimeo. It attacked a supplier and inherited access to everyone downstream.
The comparison set in these sources makes the shape clear. Ernst & Young disclosed that a third-party IT service management platform used by its tax support personnel was compromised; ShinyHunters told BleepingComputer it obtained EY credentials through a supply-chain attack and used them to reach Jira, GitHub and Azure environments. SecurityWeek reports the exposed EY data included client names, addresses, Social Security numbers, account numbers and card numbers, with 24 months of credit and identity monitoring offered. RingCentral disclosed a compromise on 28 July 2026 following what it called a "sophisticated social engineering campaign"; ShinyHunters claimed 623GB stolen, leaked a 280GB archive after RingCentral refused to pay, and Have I Been Pwned confirmed 1.6 million account records including names, emails, phone numbers and physical addresses. SecurityWeek additionally links the group to breaches at the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns.
Two lessons compound. First, the RingCentral case demonstrates the group follows through: non-payment produced a public leak within weeks. Second, a supplier compromise is a one-to-many event. MetaCompliance frames it as a contractor with a key to a building you have hardened at the front door, and the Anodot case fits exactly: one analytics vendor, an unknown number of downstream customers.
The Attack Technique
Vimeo has not published technical detail beyond removing the Anodot integration and revoking its credentials. MetaCompliance's account of stolen authentication tokens used against connected cloud resources is the only specific mechanism described, and it aligns closely with the tradecraft that primary and research sources document for this actor.
Microsoft, in a July 2026 research post, reports campaigns observed between mid-2025 and mid-2026 with tradecraft commonly associated with ShinyHunters, centred on abuse of trusted OAuth relationships for unauthorized access, exfiltration and persistence. Microsoft describes two primary intrusion paths: vishing aimed at obtaining OAuth consent, and supply chain compromise through trusted workflows and integrations such as Salesloft and Gainsight. The critical property is that inherited application and user privileges let attackers enumerate and query records "while evading conventional authentication detections." Microsoft is explicit that this was not the result of a vulnerability in Salesforce itself; the trust relationship was the attack surface. Affected tenants spanned retail, education and manufacturing.
Mitiga's research fills in the mechanics of the vishing path, tracked as UNC6040: the attacker configures OAuth Device Flow via a local Salesforce Data Loader to generate an eight-character code, then calls an English-speaking employee while impersonating IT support and talks them into entering that code on the legitimate verification page. Approval issues an access token to the attacker's Data Loader, and every subsequent action executes on behalf of the victim. Mitiga also distinguishes a second, separate campaign (UNC6395) tied to the Salesloft Drift compromise, first surfacing as Tor exit node traffic hitting Salesforce through an app most security teams could not immediately classify as authorized.
Applied to Vimeo: no Vimeo employee needed to be phished and no Vimeo system needed to be vulnerable. Compromise of Anodot's environment plus valid tokens for a sanctioned integration produced authenticated-looking access to Vimeo-connected data. That is why Vimeo's containment step was killing the integration rather than forcing a password reset, and it is consistent with the company's claim that user credentials remain secure.
What Organizations Should Do
- Inventory every OAuth-connected application and integration, including shadow IT. Mitiga's investigation began with traffic from an app that security operations could not immediately identify as authorized. You cannot revoke what you have not enumerated. Record which tenant data each integration can read, not just that it exists.
- Scope integration tokens to least privilege and set expiry. The Vimeo, EY and Salesforce cases all turn on inherited privilege surviving the supplier's own compromise. Analytics and observability vendors rarely need the read breadth they are granted at onboarding.
- Build a one-command integration kill switch and rehearse it. Vimeo's fastest effective action was deactivating all Anodot credentials and removing the integration outright. Know in advance who can do that, for which vendor, without a change-approval queue.
- Monitor for OAuth abuse specifically, not just failed logins. Microsoft's point is that this tradecraft evades conventional authentication detection because the sessions are legitimately authenticated. Enable Salesforce event monitoring or the equivalent for your SaaS estate, alert on device-flow authorizations and anomalous bulk queries by connected apps, and treat Tor or hosting-provider source IPs against sanctioned integrations as high signal.
- Train staff against device-code vishing by name. The UNC6040 flow requires a human to enter an eight-character code on a real vendor page during a phone call. Make "IT will never call and ask you to approve a code" a stated policy, and give employees a callback number to verify against.
- Treat supplier breach notification as a contractual requirement. Vimeo learned of this through Anodot's compromise, not its own telemetry. Push notification-window obligations, forensic cooperation and token-revocation commitments into vendor agreements before you need them.
- For affected individuals, follow standard post-breach hygiene. The incidents.biz checklist is sound: verify the notice through contact details found independently on the company's official site rather than links in the email, since breach notifications from widely reported incidents are a favoured phishing pretext. Given that email addresses and video titles are in scope here, expect Vimeo-themed lures referencing real account content, and change any password reused elsewhere even though Vimeo says credentials were not taken.
Bottom line: Vimeo's confirmed impact is at the low-sensitivity end of ShinyHunters' 2026 portfolio, and the company's containment was fast and correct. But the disclosed scope comes from an investigation still in progress, the only user count in circulation rests on a single source, and the entry path was a trusted supplier rather than any Vimeo failure. If your organisation grants OAuth access to analytics, support ticketing or sales-enablement vendors, this is the same campaign that has already taken 1.6 million RingCentral records to a leak site.
Sources: Vimeo confirms data breach affecting users
DigitalShield | Defending SaaS-based applications against ShinyHunters OAuth abuse... | Ernst & Young data breach claimed by ShinyHunters extortion gang | RingCentral data breach exposed info of 1.6 million accounts | ShinyHunters Claims Ernst & Young Hack - SecurityWeek | July Spotlight Breach: When Your Supplier Becomes Your Security Pro... | ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches | What to Do After a Data Breach: Checklist
Sources: Vimeo confirms data breach affecting users
DigitalShield | Defending SaaS-based applications against ShinyHunters OAuth abuse... | Ernst & Young data breach claimed by ShinyHunters extortion gang | RingCentral data breach exposed info of 1.6 million accounts | ShinyHunters Claims Ernst & Young Hack - SecurityWeek | July Spotlight Breach: When Your Supplier Becomes Your Security Pro... | ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches | What to Do After a Data Breach: Checklist