Cyber Security News

SoundCloud Data Breach Exposes 29.8 Million Personal users Details

In December 2025, music streaming platform SoundCloud disclosed a significant data breach affecting approximately 29.8 million user accounts.

The unauthorized access compromised personally identifiable information (PII), including email addresses, usernames, display names, avatars, follower statistics, and geographic location data.

The incident represents one of the most significant music platform breaches in recent years, impacting roughly 20% of SoundCloud’s total user base.

SoundCloud’s security team identified unauthorized activity on its platform during December 2025, prompting an immediate investigation into the scope and nature of the compromise.

The attackers used a flaw that let them connect public profile information to user email addresses and collect it in large amounts.

Following the discovery, SoundCloud initiated incident response procedures and notified affected users of the security incident.

Exposed Data and Attack Methodology

The compromised dataset contained 30 million unique email addresses linked to user accounts, alongside associated profile information.

Specifically, the breach included usernames, display names, avatar images, follower and following counts, and in some cases, user country information.

No passwords or payment details were stolen, but combining emails with profile data increases the risk of phishing and account takeovers.

The attackers demonstrated a systematic approach by accessing and exfiltrating large amounts of publicly available data.

Suggesting either credential compromise or exploitation of an API vulnerability that permitted unauthorized bulk data extraction.

Following the data exfiltration, the threat actors contacted SoundCloud, demanding financial compensation in exchange for non-disclosure of the stolen dataset.

When SoundCloud declined the extortion demand, the attackers subsequently released the compromised data publicly, increasing exposure risks for affected users.

Impact and Recommendations

The breach carries significant implications for user privacy and security. Email addresses linked to SoundCloud usernames significantly increase the risk of targeted phishing and social engineering attacks.

Affected users are advised to check for potential exposure using services such as HaveIBeenPwned. Attackers can leverage this data to conduct credential-stuffing attacks on other platforms where users may reuse email addresses.

SoundCloud has advised affected users to monitor their accounts for suspicious activity and implement additional security measures.

Users should enable two-factor authentication (2FA) on their SoundCloud accounts and consider changing passwords on other platforms if they reused credentials.

Organizations with employee accounts should review access logs for unauthorized activity and consider implementing email-based threat-detection policies to identify suspicious account access patterns.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago