Vimeo Anodot third-party data incident

Unauthorized access to Vimeo user and customer data resulting from a incident at analytics vendor Anodot. Vimeo-confirmed technical data, video titles, metadata, and some customer email addresses, with a later verified HIBP unique-email corpus.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to Vimeo user and customer data resulting from a incident at analytics vendor Anodot. [2]

Impact

Vimeo-confirmed technical data, video titles, metadata, and some customer email addresses, with a later verified HIBP unique-email corpus. [1][2]

Documented data types include:

  • Names — Names listed by HIBP, sometimes accompanying email addresses; Vimeo’s notice did not list names. [1][2]
  • Contact information — Customer email addresses confirmed by Vimeo in some cases and represented by HIBP’s unique-email corpus. [1][2]

A cited record reports 119,167 records (Unique email addresses in HIBP’s verified corpus; not a Vimeo-confirmed affected-person, customer, user, account, video, database, or total-row count; as of 2026-05-05). [1][2]

Vimeo said an unauthorized actor accessed certain Vimeo user and customer data as a result of the Anodot incident. [2]

Timeline

  1. Public disclosure

    Initial publication date shown by Vimeo; the preserved revision includes a May 15 update.

    [2]
  2. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Vimeo said the accessed data did not include Vimeo video content, valid user login credentials, or payment card information and that login credentials were secure. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

In its May 15 update, Vimeo said its investigation was complete and potentially impacted users and customers had been contacted as appropriate. Vimeo said it disabled all Anodot credentials, removed the Anodot integration, engaged third-party security experts, and notified law enforcement; the incident did not disrupt Vimeo systems or service. HIBP marked the Vimeo incident record verified and not fabricated. Vimeo said the accessed databases primarily contained technical data, video titles and metadata, and in some cases customer email addresses. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]