Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsHacking Group Says It’s Extorting Pornhub After Stealing Users’ Viewing Data
Hacking Group Says It’s Extorting Pornhub After Stealing Users’ Viewing Data
Cybersecurity

Hacking Group Says It’s Extorting Pornhub After Stealing Users’ Viewing Data

•December 16, 2025
0
TechCrunch (Cybersecurity)
TechCrunch (Cybersecurity)•Dec 16, 2025

Companies Mentioned

Mixpanel

Mixpanel

CoinTracker

CoinTracker

SoundCloud

SoundCloud

Salesforce

Salesforce

CRM

OpenAI

OpenAI

Why It Matters

The leak exposes intimate user behavior on a major adult platform, raising privacy and regulatory concerns, while the extortion demand adds financial risk for Pornhub. It also illustrates how third‑party analytics services can become attack vectors, prompting companies to reassess security controls.

Key Takeaways

  • •Scattered Lapsus$ Hunters claim extortion of Pornhub
  • •Data stolen via Mixpanel breach includes emails, viewing history
  • •Mixpanel lacked MFA, enabling credential compromise
  • •Hackers also hit SoundCloud, Salesforce, Gainsight
  • •Incident highlights third‑party analytics risk for premium services

Pulse Analysis

The Mixpanel incident highlights a growing blind spot in modern data architectures: reliance on third‑party analytics tools without robust security safeguards. While Mixpanel serves roughly 8,000 customers, its optional multi‑factor authentication left employee credentials vulnerable, allowing attackers to siphon raw event streams. This breach demonstrates that even well‑funded platforms can inherit risk from service providers, turning routine user‑behavior tracking into a conduit for large‑scale data exposure.

For Pornhub, the compromised dataset goes beyond generic identifiers; it contains granular viewing logs, video titles, timestamps, and geographic markers. Such detail can be weaponized for blackmail, targeted advertising, or even political manipulation, especially given the stigmatized nature of adult‑content consumption. The extortion email from Scattered Lapsus$ Hunters adds a financial dimension, pressuring the company to negotiate or risk public release of sensitive user habits. Regulators may scrutinize the breach under privacy frameworks like GDPR or CCPA, potentially resulting in fines and mandatory remediation.

The ripple effect extends to other Mixpanel clients, including SoundCloud, OpenAI, and fintech firms, underscoring a supply‑chain threat that transcends industry lines. Companies must adopt a zero‑trust stance toward third‑party integrations, enforce mandatory MFA, and regularly audit data access logs. Investing in encryption at rest and in transit, alongside incident‑response drills, can mitigate the fallout of similar attacks. As cybercriminals continue to target the data pipelines that power digital experiences, proactive governance will become a competitive differentiator for privacy‑conscious brands.

Hacking group says it’s extorting Pornhub after stealing users’ viewing data

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...