/

Hackers Claim Massive Breach of Pornhub User Data, Raising Blackmail Fears

2 mins read
[Representational Photo: Getty Images]

Hackers have claimed responsibility for stealing vast amounts of personal data linked to Pornhub, one of the world’s largest adult websites, sparking fears that users could face blackmail or extortion if the information is leaked or sold. The ShinyHunters hacking group says it has obtained 200 million records connected to the site’s premium customers.

According to cybersecurity reports, the stolen data includes highly sensitive information such as viewing histories, email addresses, activity types, locations, and specific video titles and links. While no passwords or payment details were taken, experts warn that the nature of the data could make users particularly vulnerable to coercion or reputational harm.

Pornhub confirmed that it has contacted affected customers and said the information was taken from Mixpanel, a data analytics company it previously used to track user engagement. The company, which is based in Montreal, said it stopped working with Mixpanel in 2021 and stressed that financial information and login credentials were not compromised.

Mixpanel, which disclosed its own security breach in November, denied responsibility for the alleged Pornhub data leak. In a statement, the company said it could find no evidence that the data was stolen during its earlier incident or through any other breach of its systems. Mixpanel said the data in question was last accessed in 2023 by a legitimate employee account linked to Pornhub’s parent company, adding that if the information is now in unauthorised hands, it does not believe this was due to a security failure on its side.

The breach has revived memories of earlier high-profile attacks on adult platforms, including the 2015 hacks of Ashley Madison and Adult FriendFinder, which led to the public release of user data and severe personal consequences for some victims. Cybersecurity specialists say adult site users are often targeted precisely because of the leverage such information provides.

ShinyHunters has emerged in recent years as a major threat to large organisations, frequently targeting companies that rely on Salesforce customer relationship management software. The group is known for using social engineering tactics, including posing as IT support staff and tricking employees into installing malicious software that grants access to internal systems.

Victims of ShinyHunters attacks have included major global brands such as FedEx, Disney and Hulu, Marriott, Google, Cisco, Toyota, Gap and McDonald’s. The group is also believed to overlap with other hacking networks, including Scattered Spider, which has been linked to attacks on major UK retailers.

Security researchers say these groups often rely on “vishing”, or voice phishing, to manipulate employees into handing over access. An online collective associated with these hackers has openly publicised its activities on Telegram, and investigators believe its administrator is a teenage boy based in Jordan.

Rafe Pilling, director of threat intelligence at Sophos X-Ops, said attacks like this highlight the growing danger of supply-chain breaches. He warned that even companies with strong internal security can be exposed through third-party services that do not meet the same standards. He added that ShinyHunters has been active since 2020 and is known for selling stolen data on underground forums, including BreachForums, which has recently resurfaced.

As investigations continue, cybersecurity experts are urging companies to reassess how customer data is shared with external providers, while affected users face an anxious wait to see whether the stolen information will be released or used for criminal gain.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog