Hackers claiming to be part of the group ShinyHunters say they have stolen personal data belonging to Pornhub Premium users and are demanding a Bitcoin ransom to stop the information from being released online.
The group made the claim on Tuesday, saying it would publish the data if its demands are not met.
What Was Stolen
While the full size of the breach is still unclear, the hackers shared a sample of the stolen data with Reuters. The news agency was able to partially verify it.
At least three former Pornhub customers—two men in Canada and one man in the United States—confirmed that the information linked to them was real, though it dated back several years. They asked to remain anonymous due to the sensitive nature of the issue.
ShinyHunters told Reuters they are demanding payment in Bitcoin in exchange for deleting the data and keeping it private.
Pornhub Responds
Pornhub and its parent company, Ethical Capital Partners, which is based in Ottawa, Canada, did not respond to requests for comment. The cybersecurity website Bleeping Computer first reported the breach.
Pornhub is one of the world’s most visited adult websites, claiming more than 100 million daily visits and 36 billion visits per year. While much of its content is free, its Premium service offers ad-free viewing, high-definition videos, and virtual reality content.
Link to Third-Party Company.
ShinyHunters said the stolen data involved 14 Premium users. Reuters was able to link six of those records to information from earlier data leaks stored by a dark web intelligence firm. Three of those people confirmed they had once subscribed to Pornhub Premium.
Pornhub said in a statement on December 12 that it recently experienced a cybersecurity incident involving Mixpanel, a third-party data analytics company. According to Pornhub, the incident affected a limited set of analytics data for some Premium users and occurred within Mixpanel’s systems.
Mixpanel had earlier disclosed its own security incident on November 27.
Conflicting Claims
Mixpanel denied responsibility for the stolen Pornhub data. The company said its investigation found no evidence that the data came from its November security breach.
Mixpanel stated that Pornhub data was last accessed by a legitimate employee of Pornhub’s parent company in 2023, and that if the data is now in hackers’ hands, it was not due to a Mixpanel breach.
ShinyHunters disagreed, insisting the data was connected to the Mixpanel incident. Mixpanel rejected that claim and said it had already notified all affected clients from the November breach, adding that Pornhub was not among them.
About the Hackers
ShinyHunters is a well-known hacking group linked to several major data breaches and extortion attempts in recent months. Past targets reportedly include customers of Salesforce and luxury retail brands in the United Kingdom.
Comments
Post a Comment