Hacker NewsNewsOther VideosUS NewsVideos

ShinyHunters Demands Bitcoin After Claiming 201 Million Pornhub Premium Watch and Search Records

Οι ShinyHunters έκλεψαν δεδομένα χρηστών Pornhub

Pornhub did not lose passwords. It did not lose card numbers. It did not lose government IDs. What ShinyHunters says it took is worse for a lot of the people who pay for the site: the map of what they searched, what they watched, when they watched it, and which Premium account the clicks belonged to. The group told reporters it is sitting on about 94 gigabytes and 201 million analytics records and wants Bitcoin not to publish them. Pornhub says the leak came from Mixpanel, a third-party analytics vendor, not from its own login or billing stack. Mixpanel says its November 2025 smishing incident is not the source. That three-way standoff is the story. The data, if it is real, is already gone from whoever held it first.

Reuters was able to partially authenticate some of the stolen rows. BleepingComputer published the extortion pitch. Pornhub posted a notice on December 12, 2025, warning a “limited set” of Premium users that analytics events had been exposed. None of those statements settle the chain of custody. They do settle the risk. Search terms and watch titles tied to an email and a rough location are enough to run a shakedown without ever touching a credit card.

What the thieves say they have

ShinyHunters described the haul as historical search, watch, and download activity for Premium members: customer details, email addresses, locations, video URLs and titles, keywords, activity type, and timestamps. The group put the record count at 201,211,943. That number is not the same as 201 million people. Analytics events stack. One subscriber can generate thousands of rows. The damage does not shrink just because the headcount is smaller than the row count. A single email plus a month of titles is enough to write an extortion note that sounds informed.

Pornhub’s parent, Aylo, has spent years telling advertisers and banks that the platform cleaned up after the 2020 credit-card revolt and the 2021 document-verification reset. A leak of Premium viewing history undercuts that pitch even if the core vault never opened. Intimate telemetry is the product advertisers buy. It is also the product a blackmailer buys.

The company insists passwords, payment data, and identity documents were not in the Mixpanel feed. That is plausible. Analytics tools are built to record behavior, not vaults. It is also the sentence every vendor writes after a supply-chain hit. Affected users should still treat any email that cites a specific video or search as hostile. Do not click a “verify your Premium account” link. Do not pay a stranger who claims to have the file.

Mixpanel’s denial and the 2021 cutoff

Mixpanel disclosed on November 26, 2025, that it had spotted an SMS phishing campaign on November 8 and opened an incident. A “limited set of analytics events” for some customers was affected. OpenAI later said some API users were touched. SoundCloud said roughly 28 million accounts, about a fifth of its base, had data exposed. The pattern fits ShinyHunters’ usual door: smishing or vishing an employee, then walking into a SaaS console that already holds everyone else’s logs.

Mixpanel still denies that the Pornhub file came out of that November case. The company told Reuters it found no sign the adult-site records left in that incident and noted that Pornhub stopped using Mixpanel around 2021. If that cutoff is accurate, any surviving Pornhub rows in Mixpanel’s systems would be historical, not live. Historical can still ruin a person. It also creates a fight over who was supposed to delete the archive when the contract ended.

Security researchers have floated two other explanations that do not need Mixpanel to be lying: a separate phishing hit on an employee who still had old exports, or an insider who walked a dump out the door and sold it under a famous brand. ShinyHunters has an incentive to attach every haul to a known incident. Vendors have an incentive to isolate every haul from their last incident. Users are stuck between those incentives.

The AEGIS Alliance has watched this exact vendor-to-victim hop in other files, including the 700Credit auto-finance breach and the RFID card backdoor that sat in office badges for years before anyone treated it as a product flaw. Third parties hold the interesting data because first parties do not want to build the tooling. When the third party wobbles, the first party sends a blog post.

Who ShinyHunters is when the logo is on the email

ShinyHunters has been a data-theft and extortion brand since about 2019. It does not encrypt hospitals. It steals tables and sells silence. French police arrested four alleged affiliates in June 2025. A French national, Sébastien Raoult, was extradited to the United States years earlier. The brand kept working. Google tracks overlapping crews as UNC6040, UNC6240, and a cluster of related numbers. In 2025 those crews ran a voice-phishing wave against Salesforce customers, tricking staff into connecting a malicious app to corporate CRM instances. Qantas, Allianz Life, luxury houses under Kering, Adidas, and even a Google Salesforce instance showed up in the blast radius. Krebs on Security later documented a leak site that threatened dozens of Fortune 500 names.

The Pornhub job looks smaller than the Salesforce wave and meaner in a different way. CRM dumps are business pain. Watch-history dumps are personal pain. The group told Reuters the Mixpanel incident was the source and that Bitcoin would make the file go away. Paying that bill does not retire a copy. It funds the next one.

The same crew’s methods showed up in The AEGIS Alliance’s coverage of other cyber shakedowns, from the auto-credit warehouse to broader hacker news on phishing services that rent access by the week. The tool is almost never a zero-day. The tool is a text message that looks like IT.

Why adult analytics is a special class of harm

A leaked shopping cart is embarrassing. A leaked week of adult search terms can end a marriage, a clearance, a pulpit, or a campaign. The people most exposed are not anonymous casual visitors. They are Premium subscribers, the cohort that paid and therefore left a stronger identifier. Location fields in analytics packages are often coarse, but coarse is enough when combined with a workplace email.

Privacy advocates have used the incident to argue that behavioral logs for sexual content should not live at a vendor for years after the contract dies. Europe’s regulators already treat sex-life data as a special category under GDPR. A 201-million-row file of titles and timestamps is a test of whether that category means anything when the processor is in another country and the attacker is a Telegram handle.

Users who think they might be in the set should assume phishing will follow. Messages that quote a video title are not proof the sender has the whole dump. They are proof the sender read a sample. Change the email on the account if the address is used anywhere else. Watch bank and identity channels even though cards were supposedly untouched, because credential-stuffing crews will try the address against every other login. Do not negotiate.

Aylo has not said it will pay. Mixpanel has not said it will pay. ShinyHunters does not need either of them to pay if it can sell slices of the file to smaller extortion shops. That secondary market is how these dumps actually travel. The press conference is the advertisement.

The lesson is not “stop using analytics.” Sites will keep measuring. The lesson is that a dashboard built to optimize thumbnails is also a dossier. When that dossier sits at a vendor the customer forgot it still used, the dossier is no longer under anyone’s control. Pornhub can lock its own vault. It cannot unsay a row that left through a side door in 2021 and surfaced under a ransom note in 2025.

The AEGIS Alliance will keep the hacker and technology desks on the leak site, the vendor statements, and any regulator who treats adult telemetry as ordinary marketing data. Ordinary marketing data does not usually arrive with a Bitcoin address attached.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link