Video hosting platform Vimeo has disclosed a security incident where user and customer data was exposed due to a supply chain attack targeting its third-party analytics vendor, Anodot. Attackers compromised Anodot and stole authentication tokens, which they then used to gain unauthorized access to the cloud data environments of Anodot's customers, including Vimeo's Snowflake and BigQuery instances. The notorious extortion group ShinyHunters has claimed responsibility, listing Vimeo on its leak site. Exposed data includes video metadata and some customer emails, but not video content or payment details. Vimeo has since disabled the Anodot integration and all associated credentials.
This incident is a classic supply chain attack where a less-secure third-party vendor becomes the entry point into a more secure primary target.
ShinyHunters listed Vimeo on its data leak site and claimed to have data from the company's Snowflake and BigQuery instances. This campaign was not isolated to Vimeo; gaming giant Rockstar Games was also identified as a victim of the same Anodot compromise, highlighting the widespread impact of a single vendor breach.
The core of this attack was the theft and misuse of authentication tokens. By compromising the central analytics platform (Anodot), the attackers gained a powerful pivot point. Anodot, by design, would have had persistent, trusted access tokens to its customers' data warehouses (like Snowflake and BigQuery) in order to perform its analytics functions.
Once the attackers stole these tokens from Anodot, they could directly query the customers' data warehouses, bypassing the primary target's direct perimeter defenses. This is a highly effective technique because the access requests made with the stolen tokens would appear to originate from a legitimate, trusted third-party service.
T1528 - Steal Application Access Token: The central technique of the attack, where tokens were stolen from the vendor, Anodot.T1625 - Steal or Forge Cloud Credentials: A broader classification of the token theft, specifically targeting cloud service access.T1530 - Data from Cloud Storage Object: Attackers used the stolen tokens to directly access and exfiltrate data from Vimeo's Snowflake and BigQuery cloud data warehouses.T1199 - Trusted Relationship: The attackers exploited the trusted relationship between Vimeo and its vendor, Anodot, to gain access.For Vimeo, the impact is primarily reputational. While the company emphasizes that the most sensitive data was not exposed, any unauthorized access to user data erodes trust. The incident also incurs costs for incident response, forensic investigation, and legal review.
This attack serves as a powerful case study on the systemic risk posed by supply chain vulnerabilities. The compromise of a single vendor, Anodot, had a cascading effect on multiple high-profile customers. It forces organizations to re-evaluate their third-party risk management programs and the level of trust and access granted to vendors.
No specific Indicators of Compromise were mentioned in the source articles.
Organizations can hunt for signs of similar third-party token compromise:
log_sourceSnowflake/BigQuery Audit Logscloud_observableAccess from non-standard IP rangesuser_agentUnusual User-Agent stringsVimeo's response was appropriate:
For detection, organizations should focus on D3-CUA - Cloud User Activity Analysis, specifically monitoring the behavior of third-party service accounts for anomalies.
Refined technical analysis, updated MITRE ATT&CK mappings, and new hunting hints for the Vimeo Anodot breach.
This update provides a refined technical analysis of the Vimeo data breach, incorporating updated MITRE ATT&CK mappings such as T1078.004 (Valid Accounts: Cloud Accounts), T1539 (Steal Web Session Cookie), and T1580 (Cloud Infrastructure Discovery). Additionally, new cyber observables for hunting are included, focusing on specific API endpoint monitoring and user account patterns. The incident's core details remain consistent, but this article offers a slightly different analytical perspective and explicitly lists the original news sources.
ShinyHunters leaked a 106GB data archive, confirming 119,000 Vimeo user email addresses exposed via the Anodot breach.
The notorious ShinyHunters group has publicly leaked a 106GB data archive allegedly stolen from Anodot, which includes data from Vimeo. The breach notification service Have I Been Pwned has indexed this data, confirming the exposure of 119,000 unique Vimeo user email addresses, along with names and technical metadata. This leak provides concrete evidence of the breach's scale and increases the risk of targeted phishing for affected users.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.