One of the largest data breaches in the music streaming space was recently revealed, as hackers gained access to personal information linked to nearly 29.8 million user accounts SoundCloud. The attack has raised serious questions about data security on mass-market platforms and how companies handle such crises.

SoundCloud, which was founded in 2007 with the aim of giving a platform to independent artists, has grown into one of the largest music platforms in the world, hosting over 400 million tracks from more than 40 million creators. The size of its user base makes the breach particularly serious.
See also: VS Code: Malicious AI extensions steal developer data
How the attack was revealed
The company officially confirmed the incident in mid-December, after reports of users experiencing access issues, such as “403 Forbidden”, particularly when trying to connect via VPN. The anomaly led to an internal investigation, which uncovered unauthorized activity in the platform’s internal support tools.
SoundCloud said it immediately activated its security incident response procedures and began an extensive review of its systems. According to the company, the breach involved a limited set of data, mostly information that was already publicly visible on user profiles.
SoundCloud: What data was exposed
SoundCloud maintained that no sensitive information, such as passwords or financial data, was affected. However, independent investigations revealed that the leak was more extensive than the company initially admitted.
See also: Nova Ransomware: Hackers say they breached KPMG

Have I Been Pwned , a service known for tracking data breaches, reported that the attack affected about 30 million unique email addresses , as well as data such as:
- Usernames
- Public profile names
- Avatar images
- Number of followers and following
- Country or geographic location (in some cases)
The attackers allegedly associated public profiles with private email addresses, increasing the risk of phishing, spam, and targeted scams.
ShinyHunters and blackmail attempts
According to information from BleepingComputer, the attack is being carried out by the notorious cybercrime group ShinyHunters, which has been linked to several major data breaches in recent years.
The group allegedly not only obtained the data, but also attempted to blackmail SoundCloud, using aggressive tactics such as email flooding to pressure the company, its employees, and partners.
SoundCloud later confirmed that the perpetrators made demands and attempted to cause disruption, before releasing some of the data.
A broader threat to the SaaS ecosystem
The case does not appear to be isolated. Around the same time, ShinyHunters also claimed responsibility for attacks voice phishing (vishing) targeting SSO accounts on major platforms such as Okta, Microsoft, and Google.
See also: Lazarus hackers target drone manufacturers in Europe
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Such attacks can lead to the breach of corporate SaaS services, allowing large-scale data theft and its use for financial extortion or further cybercrime.

What does this mean for users?
Even though no passwords were leaked, the exposure of emails and public data increases the risk of:
- Targeted scams
- Deceptive phishing messages
- Digital identity theft
- Malicious use of personal data
Experts recommend that users be especially careful with suspicious emails, enable two-factor authentication (2FA) , and monitor whether their information has been exposed.
See also: Gmail, Facebook, Instagram, TikTok credentials leaked online
Another bell for data security
The SoundCloud leak highlights once again how critical cybersecurity is on platforms with millions of users. As attacks become more targeted and organized, companies are being asked to invest more in prevention, transparency, and protecting their users.
The incident is a reminder that, in the digital age, data security is not a luxury — it is a necessity.
Source: www.bleepingcomputer.com
