North America
Vimeo
The broad ransomware campaign by ShinyHunters continues to send shockwaves across industries, with new high-profile victims emerging, including video platform Vimeo, digital training giant Udemy and medical device manufacturer Medtronic.
Vimeo confirmed that hackers accessed user and customer data following a breach involving a third-party vendor. The attackers reportedly gained access to databases containing technical data, video titles, metadata and customer email addresses. ShinyHunters claimed responsibility for the attack, stating that data was extracted from Vimeo’s Snowflake and BigQuery environments.
Alarmingly, the campaign continues to expand, with the group claiming to have stolen 1.4 million records from Udemy. Meanwhile, Medtronic confirmed that certain corporate IT systems were compromised, adding to the growing list of affected organizations.
How it could affect your business
Large-scale ransomware campaigns like this highlight how attacks can rapidly spread across multiple organizations and sectors. The exposed data can be reused for targeted phishing and follow-on attacks, increasing the risk for both affected companies and their partners. Organizations should strengthen user awareness, closely monitor third-party access and ensure strong detection capabilities are in place to identify suspicious activity early.