News: 0180667404

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

SoundCloud Data Breach Impacts 29.8 Million Accounts (bleepingcomputer.com)

(Tuesday January 27, 2026 @10:30PM (BeauHD) from the another-day-another-breach dept.)


A data breach at SoundCloud [1]exposed information tied to 29.8 million user accounts , according to [2]Have I Been Pwned . While SoundCloud says no passwords or financial data were accessed, attackers mapped email addresses to public profile data and later attempted extortion. BleepingComputer reports:

> The company confirmed the breach on December 15, following widespread reports from users who were unable to access SoundCloud and saw 403 "Forbidden" errors when connecting via VPN. SoundCloud told BleepingComputer at the time that it had activated its incident response procedures after detecting unauthorized activity involving an ancillary service dashboard. "We understand that a purported threat actor group accessed certain limited data that we hold," SoundCloud said. "We have completed an investigation into the data that was impacted, and no sensitive data (such as financial or password data) has been accessed. The data involved consisted only of email addresses and information already visible on public SoundCloud profiles."

>

> While SoundCloud didn't provide further details regarding the incident, BleepingComputer learned that the breach affected 20% of all SoundCloud users, roughly 28 million accounts based on publicly reported user figures (SoundCloud later published a [3]security notice confirming the information provided by BleepingComputer's sources). After the breach, BleepingComputer also learned that the ShinyHunters extortion gang was responsible for the attack, with sources saying that the threat group was also attempting to extort SoundCloud. This was confirmed by SoundCloud in a January 15 update, which said the threat actors had "made demands and deployed email flooding tactics to harass users, employees, and partners."



[1] https://www.bleepingcomputer.com/news/security/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts/

[2] https://haveibeenpwned.com/Breach/SoundCloud

[3] https://soundcloud.com/playbook-articles/protecting-our-users-and-our-service



Rumor is they're now renaming to (Score:1)

by Tablizer ( 95088 )

"SoundOnPremise"

I never understand this (Score:2)

by RitchCraft ( 6454710 )

"no passwords or financial data were accessed" - You see this all the time. A breach happens and companies almost always claim that no passwords of financial data were accessed. Why is that? Is the security on that information better? If so, then why the hell is that same security not used overall? This makes absolutely no sense.

Re: (Score:2)

by sound+vision ( 884283 )

They would have legal or contractual obligations around storing the credit card information. Probably no such obligations for the other data.

Soundcloud also makes all kind of user data available to advertisers (as usual) but also to the record industry ecosystem of labels, distributors, promoters, etc. They provide dashboards for those guys, so that API is likely where the data leaked from. Especially since they're saying "partners" were harassed.

system consumed all the paper for paging