Pornhub is at the center of a major cybersecurity case after it was allegedly blackmailed by the infamous ShinyHunters group . The case is linked to the theft of data and search and tracking history of Premium users , which came from a breach of the Mixpanel platform .
The Mixpanel breach and Pornhub's involvement
Last week, Pornhub confirmed that it was indirectly affected by a third-party security incident. Specifically, Mixpanel was breached on November 8, 2025, following attack smishing – a form of SMS phishing – that allowed attackers to gain access to internal systems.
According to an official statement from the adult platform, only a limited number of Pornhub Premium users were affected, while it is clarified that there was no direct breach of Pornhub's. Passwords, payment details and financial information were not exposed, according to the company.
See also: NexusRoute: New malware campaign targets Android users

Of particular importance is the fact that Pornhub had discontinued its partnership with Mixpanel since 2021, which suggests that the leaked data is older.
Conflicting statements and questions
Mixpanel, for its part, says that only a “limited number” of customers were affected, with companies like OpenAI and CoinTracker having already confirmed they were affected. However, after the case went public, Mixpanel openly disputed that Pornhub data came from the November breach.
In a statement, the company claims that the data was last accessed in 2023 by a legitimate employee account of Pornhub's parent company, leaving open the possibility of a leak from a different source.
What does the stolen data include?
Despite conflicting claims, the ShinyHunters group claims to have obtained 94GB of data, corresponding to more than 200 million files. According to them, this is detailed activity histories of Premium users, such as searches, views, downloads and interactions with content.
See also: French Interior Ministry suffers cyberattack
A sample of data examined by security researchers reveals the extent of the breach: users' emails, geographic locations, video URLs and titles, keywords, and precise timestamps of activity. This is information that, if made public, could cause serious personal and social exposure.

ShinyHunters and the escalation of attacks in 2025
ShinyHunters is no stranger to cybercrime. In 2025, it has been linked to a series of large-scale attacks, exploiting weaknesses in Salesforce integrations and zero-day vulnerabilities, such as in Oracle E-Business Suite (CVE-2025-61884).
More recently, the platform GainSight breach paved the way for further data theft from Salesforce enterprise environments, affecting hundreds of organizations worldwide.
The future: Ransomware-as-a-service
As if all this weren't enough, the group is also reportedly preparing its own ransomware-as-a-service platform called ShinySpid3r. This new service is expected to act as a "tool" for collaborating groups, further intensifying the threat landscape.
See also: SoundCloud confirms it suffered a data breach
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Pornhub case highlights, once again, the dangers of massive collection and storage of analytical data, but also how critical security is in the chain of third-party providers in a data-driven digital economy.
Source: www.bleepingcomputer.com
