SoundCloud Confirms Data Breach – Hackers Exfiltrated User Account Data
SoundCloud has identified a security incident involving unauthorized access to user data, resulting in the exfiltration of email addresses and public profile information from approximately 20% of its users.
SoundCloud has identified a security incident involving unauthorized access to user data, resulting in the exfiltration of email addresses and public profile information from approximately 20% of its users.
The incident was disclosed on December 15, 2025, with assurances that no sensitive information such as passwords or financial details were compromised. SoundCloud has resolved the issue, indicating no ongoing risks to service availability.
Suspicious activity was detected in an ancillary service dashboard, prompting immediate incident response actions. Security teams quickly contained the breach and engaged third-party cybersecurity experts for a forensic investigation.
Subsequent to containment, two denial-of-service (DDoS) attacks caused temporary disruptions to web access, although mobile and API services remained unaffected.
SoundCloud confirmed that the data exfiltration was limited to non-sensitive information already visible on public profiles. The table below summarizes the incident details:
Aspect Details
The incident was disclosed on December 15, 2025, with assurances that no sensitive information such as passwords or financial details were compromised.
Affected Data Email addresses; public profile information
User Impact Approximately 20% of SoundCloud users
Sensitive Data Lost None (no passwords, financial info)
Service Disruption Temporary web downtime (DDoS-related)
Ongoing Risk None; fully contained
SoundCloud, in collaboration with cybersecurity experts, has enhanced its security measures, including improved monitoring, threat detection, identity access controls, and auditing of related systems. These enhancements led to temporary VPN connectivity issues, which are being addressed.
The company emphasizes user privacy and recommends vigilance against phishing attempts. It advises the use of multi-factor authentication (MFA) and monitoring for suspicious emails.
This incident highlights the vulnerabilities of creative platforms where public data can be leveraged for targeted phishing. SoundCloud's disclosure aligns with best practices outlined by CISA and NIST, aiming to prevent larger impacts.
Users are advised to be cautious of phishing attempts, particularly those claiming to be "SoundCloud alerts," and to enable MFA where possible.
Based on reporting by Cyber Security News.
