---
title: "Vimeo Anodot third-party data incident"
description: "Evidence-backed account of Vimeo Anodot third-party data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/vimeo-anodot-third-party-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/vimeo-anodot-third-party-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/vimeo-anodot-third-party-data-incident-2026/stix.json"
---

# Vimeo Anodot third-party data incident

Unauthorized access to Vimeo user and customer data resulting from a incident at analytics vendor Anodot. Vimeo-confirmed technical data, video titles, metadata, and some customer email addresses, with a later verified HIBP unique-email corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to [Vimeo](https://vimeo.com/) user and customer data resulting from a incident at analytics vendor Anodot. [2](#source-2)

## Impact

Vimeo-confirmed technical data, video titles, metadata, and some customer email addresses, with a later verified HIBP unique-email corpus. [1](#source-1) [2](#source-2)

Documented data types include:

- Names — Names listed by HIBP, sometimes accompanying email addresses; Vimeo's notice did not list names. [1](#source-1) [2](#source-2)
- Contact information — Customer email addresses confirmed by Vimeo in some cases and represented by HIBP's unique-email corpus. [1](#source-1) [2](#source-2)

A cited record reports 119,167 records (Unique email addresses in HIBP's verified corpus; not a Vimeo-confirmed affected-person, customer, user, account, video, database, or total-row count; as of 2026-05-05). [1](#source-1) [2](#source-2)

Vimeo said an unauthorized actor accessed certain Vimeo user and customer data as a result of the Anodot incident. [2](#source-2)

## Timeline

### April 27, 2026 — Public disclosure

Initial publication date shown by Vimeo; the preserved revision includes a May 15 update. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Vimeo said the accessed data did not include Vimeo video content, valid user login credentials, or payment card information and that login credentials were secure. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

In its May 15 update, Vimeo said its investigation was complete and potentially impacted users and customers had been contacted as appropriate. Vimeo said it disabled all Anodot credentials, removed the Anodot integration, engaged third-party security experts, and notified law enforcement; the incident did not disrupt Vimeo systems or service. HIBP marked the Vimeo incident record verified and not fabricated. Vimeo said the accessed databases primarily contained technical data, video titles and metadata, and in some cases customer email addresses. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/vimeo-anodot-third-party-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Vimeo breach record

advisory · Have I Been Pwned · May 5, 2026

<https://haveibeenpwned.com/api/v3/breach/Vimeo>

<a id="source-2"></a>

### Anodot third-party security incident

official · Vimeo.com, Inc. · Apr 27, 2026

<https://vimeo.com/blog/post/anodot-third-party-security-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   2026 Vimeo data access through Anodot: Vimeo.com, Inc.
2. **Exposed Record Count · 100% confidence · current**  
   Vimeo technical, metadata, and contact-data corpus: 119,167 record
3. **Resulted In · 100% confidence · current**  
   Vimeo technical, metadata, and contact-data corpus: Vimeo said the accessed data did not include Vimeo video content, valid user login credentials, or payment card information and that login credentials were secure.
4. **Processor For · 100% confidence · current**  
   Anodot Ltd.: Vimeo.com, Inc.
5. **Resulted In · 100% confidence · current**  
   2026 Vimeo data access through Anodot: Vimeo said an unauthorized actor accessed certain Vimeo user and customer data as a result of the Anodot breach.
6. **Resulted In · 100% confidence · current**  
   2026 Vimeo data access through Anodot: In its May 15 update, Vimeo said its investigation was complete and potentially impacted users and customers had been contacted as appropriate.
7. **Resulted In · 100% confidence · current**  
   2026 Vimeo data access through Anodot: Vimeo said it disabled all Anodot credentials, removed the Anodot integration, engaged third-party security experts, and notified law enforcement; the incident did not disrupt Vimeo systems or service.
8. **Disclosed At · 100% confidence · current**  
   2026 Vimeo data access through Anodot: 2026-04-27
9. **Resulted In · 100% confidence · current**  
   Vimeo technical, metadata, and contact-data corpus: HIBP marked the Vimeo breach record verified and not fabricated.
10. **Exposed Data Category · 90% confidence · current**  
   Vimeo technical, metadata, and contact-data corpus: Names
11. **Resulted In · 100% confidence · current**  
   Vimeo technical, metadata, and contact-data corpus: Vimeo said the accessed databases primarily contained technical data, video titles and metadata, and in some cases customer email addresses.
12. **Resulted In · 100% confidence · current**  
   2026 Vimeo data access through Anodot: Vimeo technical, metadata, and contact-data corpus
13. **Exposed Data Category · 100% confidence · current**  
   Vimeo technical, metadata, and contact-data corpus: Contact information

</details>
