Full Breakdown
SoundCloud Data Breach Exposes 29.8 Million User Accounts
1/29/2026, 12:08:43 PM
Overview of the Incident
In December 2025, SoundCloud, a prominent audio streaming platform, experienced a significant data breach that impacted approximately 29.8 million user accounts, representing about 20% of its user base. The breach was attributed to the ShinyHunters hacking group, known for its focus on data exfiltration and extortion. The attackers exploited unauthorized access to an internal service dashboard, which allowed them to map hidden email addresses to publicly available profile data.
Details of the Breach
The compromised data included email addresses, usernames, display names, avatars, follower and following counts, and, in some cases, users' countries of origin. Notably, no sensitive information such as passwords or financial data was accessed. SoundCloud confirmed the breach after users reported access issues, particularly when using VPN services, which resulted in repeated 403 "Forbidden" errors.
The breach was officially disclosed by SoundCloud on December 15, 2025, following internal monitoring that flagged suspicious activity. The attackers attempted to extort SoundCloud before leaking the data online in January 2026. The dataset was subsequently indexed by the data breach notification service Have I Been Pwned, allowing affected users to verify if their email addresses were involved.
Response and Mitigation Efforts
Upon discovering the breach, SoundCloud activated its incident response protocols, isolating affected systems and engaging external cybersecurity experts to investigate the incident. The company implemented additional security measures, including tighter access controls and improved denial-of-service protection. However, the breach led to operational disruptions, including denial-of-service attacks that temporarily affected platform access.
Criticism & Opposition
Despite SoundCloud's prompt response, cybersecurity experts have raised concerns about the implications of the breach. The aggregation of public profile data with private email addresses increases the risk of targeted phishing and social engineering attacks. Approximately 67% of the exposed email addresses were already present in the Have I Been Pwned database, indicating that many users had been affected by previous breaches and may be at heightened risk of credential stuffing attacks.
Official Statements & Responses
SoundCloud stated, "We understand that a purported threat actor group accessed certain limited data that we hold. We have completed an investigation into the data that was impacted, and no sensitive data (such as financial or password data) has been accessed." The company emphasized its commitment to transparency and user safety while acknowledging the operational challenges posed by the breach.
What's Next
As the fallout from the breach continues, SoundCloud has not yet disclosed whether all affected users will be individually notified. The incident serves as a reminder of the growing trend in cybercrime, where attackers exploit publicly available information by combining it with private identifiers. Users are urged to remain vigilant for suspicious messages and consider implementing security measures such as multi-factor authentication.
Verbatim Quotes
- “The impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the user's country. The attackers later attempted to extort SoundCloud before publicly releasing the data the following month.” — Have I Been Pwned
- “We have completed an investigation into the data that was impacted, and no sensitive data (such as financial or password data) has been accessed.” — SoundCloud
This breach highlights the persistent risks associated with credential-based attacks on cloud platforms and underscores the importance of robust cybersecurity measures for both users and service providers.
