Skip to main content
Breach Signal

Breach report

Media

SoundCloud

SoundCloud confirms breach after member data stolen, VPN access disrupted

SoundCloud confirmed in December 2025 that attackers had mapped email addresses to public profile data for about a fifth of its users, with the ShinyHunters extortion gang allegedly behind the theft and a later public leak.

Reported by BleepingComputer

Records exposed

29.8M

About 29.8 million accounts (roughly 20% of users)

Scale vs. largest on file

When
2025
How they got in
Unauthorized access to an ancillary service dashboard; extortion by ShinyHunters
Sector
Media

In mid-December 2025, users of the music streaming platform SoundCloud who connected through virtual private networks began encountering access errors. On December 15, SoundCloud confirmed that it had detected unauthorized activity in an ancillary service dashboard and that the changes it made to contain the incident had disrupted VPN connectivity. The company acknowledged that data on members had been stolen.

SoundCloud said the attackers had obtained email addresses along with information already visible on public profiles. It stated that no sensitive data such as passwords or financial information had been accessed. The company estimated that about 20 percent of its users were affected. Reporting attributed the theft to ShinyHunters, an extortion group responsible for a string of high-profile data thefts in 2024 and 2025, which allegedly attempted to pressure the company into paying to keep the data private. SoundCloud also experienced denial-of-service attacks that temporarily knocked its website offline following its response.

In January 2026, after the extortion attempt failed to produce a payment, the data was released publicly. Breach-notification service Have I Been Pwned added about 29.8 million unique email addresses, describing the leak as data that allowed public SoundCloud profile information to be linked to users' email addresses. Fields included names, usernames, avatars, follower and following counts and, in some cases, locations.

No regulatory penalties had been announced as of the leak, and SoundCloud did not detail how the attackers gained access to the dashboard. The absence of passwords reduced the risk of direct account takeover, but security experts noted that a large list connecting email addresses to music-platform identities, including artists and creators, is valuable for phishing and impersonation, particularly schemes targeting musicians with fake distribution or promotion offers.

The SoundCloud incident fits a pattern seen across 2025, in which extortion crews targeted internal tools, dashboards and third-party integrations rather than core production systems, then threatened to leak data if companies refused to pay. It also illustrates how data that seems low-risk in isolation, such as public profiles, becomes more dangerous when joined to private contact details. For platforms, the lesson is to lock down administrative and ancillary tools with the same rigor as customer-facing systems.

More from the wire

More in Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.