Be careful to watch movies too. ðĻ
The orange-and-black video platform was targeted for extortion by hackers ShinyHunters after reports of Premium users' activity data were stolen and could be made public if they refused to pay a ransom.
.
The source confirmed that this incident was not directly caused by the penetration of the platform's systems, but was the result of a data leak by Mixpanel, an analytics Vendor service provider that was attacked by SMS Phishing or Smishing on November 8, 2025. The affected data was only a partial Premium user and no key data like passwords or payment data was dropped.
.
What has generated great concern is the type of data claimed to have been stolen. The ShinyHunters group says it possesses about 94GB of data consisting of over 200 million data, which is retroactive activity data of Premium users such as search history, viewing and video downloads.
.
From a sample of the information that was revealed to the cybersecurity media, it was found to be highly sensitive. Both user email, URL location, and video name visited, relevant keywords, as well as time of access, which can clearly relate to the user's personal identity and behavior.
.
The platform provider stated that it had discontinued Mixpanel since 2021, making the disconnected data a retrospective analysis, while Mixpanel further clarified that it had found no evidence that it was from a recent attack and indicated that the data was last accessed by the parent company's employee account in 2023.
.
This event clearly reflects the risk of an attack through the software used by the organization or the Supply Chain Attack, and underscores that the user's personal data can be at risk even if the platform's core systems are not directly penetrated.
.
Source: bleepingcomputer































































































































