Briefing

Vimeo Data Breach Exposes Personal Information of 119,000 People

security
by Sergiu Gatlan ·

Patch: Disable all Anodot credentials and remove the Anodot integration from your Vimeo environment immediately.

What to do now

Patch: Disable all Anodot credentials and remove the Anodot integration from your Vimeo environment immediately.

Summary

Vimeo, a video hosting platform with 300 million users, 1,100 employees, and $417 million FY2024 revenue, disclosed a breach on April 27 that stemmed from its Anodot integration. The attack accessed technical data, video titles, metadata, and some email addresses but did not compromise login credentials or payment card information, and caused no service disruption.

Vimeo immediately disabled all Anodot credentials, removed the integration, engaged third‑party security experts, and notified law enforcement. ShinyHunters leaked a 106 GB archive of the stolen data, exposing 119,200 email addresses and names. The group also targeted Salesforce but was blocked by AI detection and has claimed other breaches.

This incident highlights the risk of third‑party integrations and the importance of rapid credential revocation and incident response.

Key changes

  • 119,200 email addresses and names exposed in the breach
  • 106GB archive of stolen documents leaked by ShinyHunters
  • Anodot credentials were disabled and the integration removed from Vimeo systems
  • No login credentials or payment card information were accessed
  • Vimeo reported no service disruption or data loss beyond the exposed data
  • Third‑party security experts were engaged and law enforcement notified

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting