Skip to main content
Security Products

Shiny Hunters Claims Attacks on Vimeo and Carnival Corporation

Shiny Hunters Claims Attacks on Vimeo and Carnival Corporation Image: Primary
The ransomware group Shiny Hunters has claimed responsibility for attacks on video platform Vimeo and cruise operator Carnival Corporation, with a ransom deadline set for April 30, 2026. Vimeo said its internal incident response teams and an external forensic cybersecurity firm are investigating the claims. The company confirmed it does not intend to pay the ransom and stated that critical data including video content, payment information, and user login credentials remain uncompromised. According to information on a Telegram channel linked to Shiny Hunters, the Vimeo breach may have originated through unauthorized access to Vimeo's Anodot analytics platform. Attackers allegedly gained access to certain credentials via that route. Meanwhile, Shiny Hunters also claimed to have breached Carnival Corporation, saying the attack exposed data belonging to approximately 8.7 million customers. The group said compromised information included names, email addresses, contact details, and dates of birth. Carnival responded that the attack stemmed from the compromise of a single user account and that the situation has been brought under control. The company said it has strengthened access controls, enhanced monitoring, and conducted a security review. Shiny Hunters has been particularly active since February 2025, reportedly focusing on organizations connected to Salesforce environments. Both Vimeo and Carnival are believed to fall within this broader targeting pattern, highlighting potential risks associated with third-party integrations and cloud-based services.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Cybersecurity Insiders and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

Port of Los Angeles reports 120 million cyberattack attempts

The Port of Los Angeles foiled more than 120 million cyberattack attempts in August, according to Bloomberg. The U.S.'s busiest container port for global trade faces a persistent operational threat while navigating shifting tariff...

Security
Security

Cisco warns of actively exploited ISE authentication bypass

Cisco warned that CVE-2026-76460, a maximum-severity flaw in Identity Services Engine and ISE Passive Identity Connector, is being actively exploited. The reported API authentication-control weakness can let an unauthenticated rem...

Capital Security
Capital Security

Comp AI raises $34 million Series A for compliance platform

Cybersecurity and compliance startup Comp AI has raised a $34 million Series A led by Roo Capital and Grand Ventures. The company says its platform uses AI agents to draft security policies, collect audit evidence and continuousl...

Capital Robotics
Capital Robotics

Treble raises €15 million for acoustic AI simulation

Reykjavík-based Treble raised approximately €15 million in a Series A-2 round led by Paladin Capital Group, bringing its total funding to €36 million. Treble's cloud platform models sound in physical spaces to create synthetic aud...

Science
Science

Phase-one mesothelioma study reports PRX3 inhibitor results

Researchers at the University of Vermont and collaborators reported phase-one results for RSO-021, a clinical formulation of thiostrepton, in relapsed mesothelioma. In 15 patients, the trial controlled disease progression in 67%;...

Robotics Science
Robotics Science

MIT demonstrates reconfigurable robotic optics lab

MIT researchers demonstrated a reconfigurable robotic optics lab that autonomously assembled and tuned a tabletop laser cavity. The seven-jointed arm picked, placed and adjusted optical components, completing 50 maneuvers within 3...