HomeSecuritySoundCloud: Data breach affects 29.8 million accounts

SoundCloud: Data breach affects 29.8 million accounts

One of the largest data breaches in the music streaming space was recently revealed, as hackers gained access to personal information linked to nearly 29.8 million user accounts SoundCloud. The attack has raised serious questions about data security on mass-market platforms and how companies handle such crises.

SoundCloud Data Breach

SoundCloud, which was founded in 2007 with the aim of giving a platform to independent artists, has grown into one of the largest music platforms in the world, hosting over 400 million tracks from more than 40 million creators. The size of its user base makes the breach particularly serious.

See also: VS Code: Malicious AI extensions steal developer data

How the attack was revealed

The company officially confirmed the incident in mid-December, after reports of users experiencing access issues, such as “403 Forbidden”, particularly when trying to connect via VPN. The anomaly led to an internal investigation, which uncovered unauthorized activity in the platform’s internal support tools.

SoundCloud said it immediately activated its security incident response procedures and began an extensive review of its systems. According to the company, the breach involved a limited set of data, mostly information that was already publicly visible on user profiles.

SoundCloud: What data was exposed

SoundCloud maintained that no sensitive information, such as passwords or financial data, was affected. However, independent investigations revealed that the leak was more extensive than the company initially admitted.

See also: Nova Ransomware: Hackers say they breached KPMG

SoundCloud: Data breach affects 29.8 million accounts

Have I Been Pwned , a service known for tracking data breaches, reported that the attack affected about 30 million unique email addresses , as well as data such as:

  • Usernames
  • Public profile names
  • Avatar images
  • Number of followers and following
  • Country or geographic location (in some cases)

The attackers allegedly associated public profiles with private email addresses, increasing the risk of phishing, spam, and targeted scams.

ShinyHunters and blackmail attempts

According to information from BleepingComputer, the attack is being carried out by the notorious cybercrime group ShinyHunters, which has been linked to several major data breaches in recent years.

The group allegedly not only obtained the data, but also attempted to blackmail SoundCloud, using aggressive tactics such as email flooding to pressure the company, its employees, and partners.

SoundCloud later confirmed that the perpetrators made demands and attempted to cause disruption, before releasing some of the data.

A broader threat to the SaaS ecosystem

The case does not appear to be isolated. Around the same time, ShinyHunters also claimed responsibility for attacks voice phishing (vishing) targeting SSO accounts on major platforms such as Okta, Microsoft, and Google.

See also: Lazarus hackers target drone manufacturers in Europe

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Such attacks can lead to the breach of corporate SaaS services, allowing large-scale data theft and its use for financial extortion or further cybercrime.

SoundCloud: Data breach affects 29.8 million accounts

What does this mean for users?

Even though no passwords were leaked, the exposure of emails and public data increases the risk of:

  • Targeted scams
  • Deceptive phishing messages
  • Digital identity theft
  • Malicious use of personal data

Experts recommend that users be especially careful with suspicious emails, enable two-factor authentication (2FA) , and monitor whether their information has been exposed.

See also: Gmail, Facebook, Instagram, TikTok credentials leaked online

Another bell for data security

The SoundCloud leak highlights once again how critical cybersecurity is on platforms with millions of users. As attacks become more targeted and organized, companies are being asked to invest more in prevention, transparency, and protecting their users.

The incident is a reminder that, in the digital age, data security is not a luxury — it is a necessity.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS