
Hackers associated with the ShinyHunters collective are extorting Pornhub after obtaining highly sensitive analytics data that links some Pornhub Premium users’ email addresses to detailed viewing and search activity, via third-party analytics provider Mixpanel rather than a direct breach of Pornhub’s core systems.
Story Highlights
- ShinyHunters hackers extort Pornhub with stolen Premium user data.
- Data includes sensitive viewing and search history linked to email addresses.
- Incident stems from a breach of the analytics provider Mixpanel, not Pornhub itself.
- Privacy risk for users as hackers threaten to publicly release data.
ShinyHunters Exploit Analytics Weakness
On November 8, 2025, a breach occurred at Mixpanel, a third-party analytics provider, through a smishing attack, compromising its systems. This breach affected various companies, with Pornhub being one of the most notable victims. ShinyHunters, a hacking group, claims to have stolen around 94 GB of Pornhub Premium analytics data, which includes email addresses, locations, and detailed viewing and search histories.
The hackers are actively extorting Pornhub, threatening to release this sensitive data if a ransom is not paid. The data’s sensitivity lies not in financial information but in the personal and potentially embarrassing nature of users’ viewing habits being exposed. This situation highlights vulnerabilities in reliance on third-party analytics platforms, where a breach outside the main service can still lead to significant privacy risks.
Response from Pornhub and Mixpanel
Pornhub’s parent company, Aylo, has acknowledged the cybersecurity incident, emphasizing that Pornhub’s own systems were not breached and that critical information such as passwords and payment data remained secure. The incident is attributed to third-party analytics managed by Mixpanel.
Mixpanel, on the other hand, disputes that the stolen data originated from their recent breach, suggesting instead that the data accessed was last handled by a legitimate Aylo employee account in 2023. This discrepancy leaves unresolved questions about the exact source and timeline of the data’s exposure.
Privacy Concerns and Industry Implications
The exposure of Pornhub Premium users’ viewing habits poses a significant privacy threat. The sensitive nature of the data, coupled with the potential for public embarrassment, places users at risk of targeted harassment, doxxing, and social stigmatization. This incident underscores the importance of robust data protection practices, particularly in industries dealing with sensitive personal data.
As the extortion attempt unfolds, the incident serves as a cautionary tale about the interconnected nature of digital services and the cascading effects of breaches within third-party providers. Companies must reassess their data security measures and third-party relationships to mitigate similar risks in the future.
Sources:
Le Monde: Pornhub hacker group threatens to leak list of premium users
BleepingComputer: PornHub extorted after hackers steal Premium member activity data
TechCrunch: Hacking group says it’s extorting Pornhub after stealing users’ viewing data
DataBreach.com: It’s real—Pornhub data breach exposes search history of Premium users







