Vimeo has announced a data exposure incident impacting a portion of its users and customers, resulting from a breach involving its third-party analytics provider, Anodot. The company confirmed that an unauthorized actor accessed certain datasets as a result of the compromise. According to Vimeo, the impacted data primarily includes technical information such as video titles and metadata. In some instances, customer email addresses were also exposed. However, the company emphasized that no video content, account credentials, or payment card information were compromised, and its platform operations remain unaffected. The breach has been linked to the cyber extortion group ShinyHunters, which has claimed responsibility and threatened to release the stolen data unless a ransom demand is met. The group also issued warnings indicating potential further disruptions. The root cause of the incident has been traced to compromised authentication tokens within Anodot’s environment. These tokens were reportedly used to access customer systems, particularly cloud data platforms such as Snowflake and Google BigQuery, enabling data exfiltration across multiple organizations. In response, Vimeo has revoked all credentials associated with Anodot and removed the integration from its systems. The company is actively investigating the incident with the support of third-party cybersecurity experts and has notified relevant law enforcement authorities. Vimeo stated that it will continue to provide updates as the investigation progresses and more details become available.
Vimeo has confirmed a data breach involving approximately 119,000 email addresses, stemming from a compromise of its third-party analytics provider, Anodot. The incident did not or...
According to security experts, there is an ongoing cyber threat against agentic AI systems, whereby hackers are misusing the skill ecosystem of OpenClaw to spread malware. The use ...
Salesforce has addressed multiple high-impact vulnerabilities in its Marketing Cloud (SFMC) platform that could have enabled attackers to access sensitive marketing data across ten...