Cyber Security News

PornHub Breached by ShinyHunters Group and Premium Members’ Data Stolen

The notorious hacking collective ShinyHunters has claimed responsibility for a major data breach at Mixpanel, a popular analytics provider, exposing limited user data tied to Pornhub Premium accounts.

The incident, which has only affected select Premium subscribers, has raised concerns within the cybersecurity community. Although Pornhub emphasizes that this was not a direct breach of its systems, the situation highlights the risks associated with third-party vendors managing sensitive analytics data.

ShinyHunters, known for high-profile leaks such as the LinkedIn data dumps, publicly claimed responsibility for the Mixpanel breach on BreachForums.

They advertised “fresh Pornhub Premium user analytics” among datasets from victims like Google and ChatGPT. Security researchers confirmed the group’s post aligns with Mixpanel’s internal notification to clients.

PornHub Breached by ShinyHunters

Pornhub’s official statement clarifies the scope: the breach occurred entirely within Mixpanel’s environment, involving a “limited set of analytics events” for some Premium users.

Crucially, no passwords, credentials, payment details, or government IDs were compromised. Pornhub ceased using Mixpanel in 2021, but legacy user-interaction data, such as session logs or behavioral metrics, may have been scraped.

Affected DataStatusRisk Level
Analytics events (e.g., session data)Exposed (limited users)Low
Passwords/credentialsNot exposedNone
Payment/financial infoNot exposedNone
Government IDsNot exposedNone

Pornhub launched an internal probe immediately upon Mixpanel’s alert, enlisting cybersecurity experts and coordinating with authorities. “We are working diligently to determine the nature and scope,” the company stated, committing to “best practices in cybersecurity and international privacy standards.”

Users are urged to monitor accounts for phishing or odd activity. Enable multi-factor authentication (MFA) and scan for malware, experts advise. Pornhub reiterated: protecting its community remains the top priority.

This event echoes supply-chain vulnerabilities seen in SolarWinds and MOVEit attacks. Mixpanel’s breach highlights how dormant vendor ties can resurface risks years later. As ShinyHunters peddles the data, affected users should check Have I Been Pwned for updates.

Avoid responding to phishing emails claiming to be from Pornhub. No password resets are required at this time, as login credentials were not affected.

Mixpanel spokesperson said to CybersecurityNews, “Mixpanel is aware of reports that Pornhub has been extorted with data that that was allegedly stolen from us. We can find no indication that this data was stolen from Mixpanel during our November 2025 security Incident or otherwise. The data was last accessed by a legitimate employee account at Pornhub’s parent company in 2023. If this data is in the hands of an unauthorized party, we do not believe that is the result of a security incident at Mixpanel.”

Dr. Ilia Kolochenko, CEO at ImmuniWeb, said to CybersecurityNews that “If the allegations that 201,211,943 records of Pornhub’s premium users were compromised – including detailed historical search, watch, and download activity – are true, this data breach may dethrone the notorious data breach of Adult Friend Finder (AFF) in 2016. The AFF breach happened before triple extortion (i.e. when both the breached company and its users are demanded to pay ransom) became a mainstream, but caused numerous suicides, layoffs, divorces and political scandals, let alone protracted damage to mental and psychological health of the victims.”

“If the reported Pornhub data breach is as big and as recent as claimed by ShinyHunters, the consequences may be much worse than the AFF breach, causing irreparable harm to victims including politicians and celebrities. Moreover, at ImmuniWeb, we have already witnessed cases when cybercrime groups threaten their victims to “poison major LLMs” with victim’s compromised data if the victim does not pay. Eventually highly sensitive victim data can be exposed in answers from AI chatbots when the victim’s name is entered as an input query. These damaging results can hardly be removed: even if top lawyers work on the case, full removal make take weeks or even months for technical reasons.”

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago