Audio streaming platform SoundCloud has confirmed that recent outages and VPN connection issues were caused by a security breach, in which threat actors stole a database exposing email addresses and profile information users'.

The revelation follows widespread reports from users who were unable to access SoundCloud when connected via VPN, resulting in the site displaying “403 forbidden” errors.
See also: Chrome extension lets AI intercept user conversations
In a statement shared with BleepingComputer, SoundCloud said it detected unauthorized activity involving a service backend. The company says it immediately activated its cyber incident response procedures.
SoundCloud – Data Breach
SoundCloud acknowledged that a threat actor gained access to some of its data, but said the report was limited in scope. “We understand that a group of threat actors gained access to limited data that we maintain,” SoundCloud told BleepingComputer.
“We have completed an investigation into the data that was affected and no sensitive data (such as financial or passwords) was exposed. The data involved only contained email addresses and information that is already visible on public SoundCloud profiles.“.

BleepingComputer has learned that the breach affects 20% of SoundCloud users, which could mean around 28 million accounts based on publicly reported user numbers.
See also: French Interior Ministry suffers cyberattack
The company said it is confident that all unauthorized access to SoundCloud’s systems has been blocked and that there is no further risk to the platform. Working with third-party cybersecurity experts, the company has taken additional steps to security its: improving threat monitoring and detection, reviewing identity and access controls, and evaluating related systems.
However, the company's response also included a settings change that disrupted VPN connectivity to the site. SoundCloud has not provided a timeline for when VPN access will be fully restored.
After responding to the incident, SoundCloud also faced denial-of-service attacks that temporarily disabled the availability of the site.
See also: Abuse of Paypal for phishing attacks

While SoundCloud has not shared details about the threat actor behind the breach, BleepingComputer has received a tip that states that the extortion gang ShinyHunters is responsible. It is said that ShinyHunters is now blackmailing SoundCloud after allegedly stealing a database of user information.
ShinyHunters is also responsible for the recent PornHub.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
