Hackers have claimed possession of over 200 million records detailing the private viewing habits of Pornhub Premium users, turning a third-party analytics breach into a high-stakes extortion nightmare. The notorious group ShinyHunters, part of a broader coalition sometimes known as Scattered Lapsus$ Hunters and linked to Scattered Spider tactics, has directly threatened Pornhub with data exposure unless a ransom is paid. This incident exposes not only personal privacy risks but also the evolving sophistication of cybercriminal alliances in 2025.
The breach originated at Mixpanel, Pornhub’s former analytics provider, on November 8, 2025, when attackers used targeted SMS phishing to compromise employee accounts and gain system access. They then exfiltrated historical data retained from Pornhub’s partnership, which ended in 2021. Pornhub issued its official security notice on December 12, 2025, confirming the impact on select Premium users and stressing that no direct compromise of its systems occurred. No passwords, payment details, or financial information were involved.
ShinyHunters has advertised the data on underground forums, sharing verified samples that include emails, approximate locations, video titles, URLs, search queries, activity types (such as watches or downloads), and timestamps. The group claims 94GB encompassing 201,211,943 records from pre-2022 activity. Mixpanel disputes the data’s origin in their November incident, stating it was last legitimately accessed in 2023. This supply-chain attack affected other clients, such as OpenAI, underscoring how legacy vendor data can create ongoing vulnerabilities.
The exposure of such intimate behavioral logs poses severe threats, from targeted blackmail threatening to reveal habits to contacts or employers, to enhanced phishing using personal details. In adult content contexts, risks amplify for individuals in conservative areas or sensitive roles, potentially leading to harassment or career damage. Experts draw parallels to past breaches but note that the detailed logs here could intensify harm if they are circulated.
ShinyHunters’ 2025 activities demonstrate a tactical evolution, incorporating Scattered Spider’s vishing and helpdesk impersonation techniques for initial access, often targeting SaaS platforms such as Salesforce. This collaboration has fueled major incidents, blending data theft with extortion across sectors. Broader cybercrime trends reveal groups leveraging AI for smarter operations, including generating personalized phishing emails, adaptive malware, and black-hat SEO to manipulate search results and drive traffic to malicious sites that distribute stealers like Vidar or Lumma.
Pornhub has initiated an internal probe with experts and law enforcement, advising vigilance against suspicious communications. Users face no need for password resets since credentials remain secure. This case highlights the persistent dangers in supply chains and the need for stricter data retention policies among vendors.
To safeguard against similar fallout, enable app-based two-factor authentication over SMS. Use a password manager for unique credentials and maintain separate email addresses for sensitive accounts. Regularly check exposure via tools like Have I Been Pwned. Beware of unsolicited ransom demands or “deletion” offers, which are often secondary scams.
Ultimately, as groups like ShinyHunters integrate AI and alliances for efficiency, breaches grow more targeted and evasive. Organizations must prioritize third-party risk audits, while individuals assume shared data carries long-term exposure risks. No full leak has surfaced yet, but ongoing extortion signals the high value criminals place on such compromising information.


