SoundCloud Data Breach Exposes 29.8 Million Personal users Details
On December 2025, SoundCloud, a music streaming platform, reported a data breach that impacted approximately 29.8 million user accounts. The breach involved unauthorized access to personally identifiable information (PII), such as email addresses,…
On December 2025, SoundCloud, a music streaming platform, reported a data breach that impacted approximately 29.8 million user accounts. The breach involved unauthorized access to personally identifiable information (PII), such as email addresses, usernames, display names, avatars, follower statistics, and location data.
The breach affected around 20% of SoundCloud's user base, making it a significant security incident in the music streaming industry. SoundCloud's security team detected the unauthorized activity in December 2025, which led to a thorough investigation into the incident.
The breach resulted in the exposure of 30 million unique email addresses linked to user accounts, along with related profile information. While no passwords or payment details were compromised, the combination of email addresses with profile data heightens the risk of phishing and account takeovers.
Attackers employed a method that allowed them to link public profile information to user email addresses, enabling large-scale data collection. This suggests the possibility of either credential compromise or exploitation of an API vulnerability that facilitated unauthorized bulk data extraction. Subsequently, the threat actors contacted SoundCloud to demand financial compensation for non-disclosure of the stolen data. Upon refusal, the attackers publicly released the compromised data.
On December 2025, SoundCloud, a music streaming platform, reported a data breach that impacted approximately 29.8 million user accounts.
The data breach has serious implications for user privacy and security. Linking email addresses to SoundCloud usernames increases the risk of targeted phishing and social engineering attacks. Users are advised to check for potential exposure using services like HaveIBeenPwned .
To mitigate risks, SoundCloud advises affected users to monitor their accounts for suspicious activities and enable two-factor authentication ( 2FA ). Additionally, users should consider changing passwords on other platforms if credentials are reused.
For organizations with employee accounts on SoundCloud, it is recommended to review access logs for unauthorized activities and implement email-based threat-detection policies to identify unusual account access patterns.
Based on reporting by Cyber Security News.
