Ransomware victim disclosure
← All victimsVimeo, Inc.
Claimed by shinyhunters · listed 23 days ago
Status timeline
- Listed
Apr 28, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- US
- Sector
- Technology
- Listed on leak site
- Apr 28, 2026
About the victim
AI dossier — public-source company profileVimeo, Inc. is a US-based video hosting, sharing, and streaming platform headquartered in New York, NY. The company provides cloud-based video tools and hosting services to businesses and creators worldwide. Vimeo serves millions of users and businesses across various industries with SaaS video solutions.
- Industry
- Video Hosting & Streaming Technology
- Employees
- 1001-5000
- Founded
- 2004
Attack summary
Severity: high — The claim involves exfiltration of cloud data warehouse contents (Snowflake and BigQuery), which typically contain large volumes of business analytics, user, and potentially PII data at scale; the attack vector is a third-party (Anodot) supply chain compromise, increasing credibility. No confirmed proof files are published yet, but the disclosed status is 'data_published' and the threat involves significant business and potentially user data.ShinyHunters claims to have compromised data from Vimeo's Snowflake and Google BigQuery cloud data warehouse instances via a third-party vendor, Anodot.com, and is threatening to leak the exfiltrated data if payment is not made by 30 April 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Snowflake instance data
- BigQuery instance data
- Third-party vendor-accessible cloud data
What the group claims
Your Snowflake and Bigquery instances data was compromised thanks to Anodot.com. Pay or Leak. This is a final warning to reach out by 30 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 28 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 23 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
