ShinyHunters Breached Analytics Platform Anodot, Then Pivoted to Vimeo, Rockstar Games, and Zara via Snowflake
The ShinyHunters threat group compromised Anodot, a data anomaly detection SaaS, and used its Snowflake integrations to steal user data from Vimeo, Rockstar Games, and Zara in a third-party supply chain attack confirmed May 1, 2026.
ShinyHunters didn’t attack Vimeo, Rockstar Games, or Zara directly. They attacked Anodot — and then used Anodot’s credentials to walk into their targets’ Snowflake accounts.
The breach was confirmed May 1, 2026 when Vimeo published a public incident notice acknowledging that user data had been exposed through a third-party analytics provider. BleepingComputer identified that provider as Anodot, a data anomaly detection platform used by enterprise clients to monitor metrics across their data warehouses.
The Attack Path
ShinyHunters breached Anodot in early April 2026. The method of initial access has not been publicly disclosed, but Anodot held service account credentials with read access to customer Snowflake environments — a standard architecture for analytics SaaS platforms that need to query client data lakes.
Once inside Anodot’s systems, the attackers extracted those integration credentials and used them to directly query Snowflake accounts belonging to Anodot’s clients. The data they pulled from Vimeo included email addresses, video titles, and metadata. No passwords, no payment card data, and no video content was accessed.
Rockstar Games and Zara confirmed similar exposure — email addresses and account metadata but no credentials or financial data.
ShinyHunters set a ransom deadline of April 30, 2026. Vimeo’s response was to disable all Anodot credentials, rotate affected service accounts, and notify law enforcement and impacted users. At time of publication, no ransom payment has been confirmed.
The Snowflake Vector Is Not New
This is the third major breach in 14 months that followed the same supply chain → Snowflake pattern. In 2025, Ticketmaster, Santander, AT&T, and over 160 other companies were compromised through stolen Snowflake credentials, with ShinyHunters claiming responsibility for much of that campaign too.
The pattern exploits a structural reality: companies give their SaaS vendors broad data access to enable the analytics product to work. Those vendor environments are frequently less hardened than the client’s own infrastructure, and the credentials are often long-lived service accounts rather than short-duration tokens with MFA enforcement.
Snowflake now requires MFA on all accounts and supports network policies that whitelist specific IPs. But enforcement is the client’s responsibility — and clearly many organizations hadn’t enforced it on their vendor-held credentials.
What to Do
If your organization uses any third-party analytics or data observability SaaS with access to your Snowflake environment:
- Audit all service account credentials that external vendors hold for your Snowflake environment.
- Enable MFA on all Snowflake users, including service accounts where the tooling supports it.
- Apply network policies to restrict Snowflake access to known vendor IP ranges.
- Set credential expiration on integration service accounts — indefinite-lifetime credentials are the key enabler of this attack pattern.
- Review Snowflake query history for the past 60–90 days for anomalous access patterns from vendor account identifiers.
Snowflake’s Trust Center provides tools for auditing account-level MFA adoption and network policy coverage.
The ShinyHunters Pattern
ShinyHunters operates primarily as a financially motivated extortion group. Their approach is consistent: breach a SaaS intermediary, harvest downstream access, set ransom deadlines. When targets don’t pay, the data gets posted to BreachForums.
The data taken from Vimeo, Rockstar, and Zara — email addresses and account metadata — has modest intrinsic value. The leverage comes from the reputational cost of a public breach notice and the threat of the data being used for phishing campaigns against their users. Vimeo’s user base in particular is professional video creators and enterprise clients — a high-value phishing target.
Rotate your vendor credentials. Audit your SaaS supply chain. The vector is known, the fix is available.
Related reading
- Cybersecurity ShinyHunters Breach Canvas LMS: 275 Million Students Exposed Across 8,800 Universities
- Cybersecurity ShinyHunters Breaches Rockstar Games Through Third-Party SaaS, Releases Data After Ransom Refusal
- Cybersecurity China Weaponizes the Tata Electronics Breach to Undercut India's iPhone Buildout