[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2hcqq0hhpg9mj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"6a452308a20f867c8ba8e722","SoundCloud","SoundCloud 2025 Data Breach","soundcloud","soundcloud.com","2025-12-15T00:00:00.000Z","2026-01-27T01:13:16.000Z",null,"2026-07-21T16:54:11.093Z","Verified breach record","https:\u002F\u002Fsoundcloud.com\u002Fplaybook-articles\u002Fprotecting-our-users-and-our-service",[16,18,19],"https:\u002F\u002Fau.pcmag.com\u002Fsecurity\u002F114866\u002Fhackers-steal-limited-data-on-20-of-soundcloud-users","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhave-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts\u002F",29815722,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Critical",[31,32,33,34,35,36],"Avatars","Email addresses","Geographic locations","Names","Profile statistics","Usernames","\u003Cp>The 2025 SoundCloud data breach involved unauthorized activity in an ancillary service dashboard that allowed 29,815,722 unique email addresses to be mapped to public profile information. SoundCloud disclosed the incident on December 15, 2025 and said approximately one in five users was affected. The verified scope is email addresses and public profile fields, not passwords or financial data.\u003C\u002Fp>\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\u003Cp>Verified data classes are avatars, email addresses, geographic locations, names, profile statistics, and usernames. Profile statistics include follower and following counts, while country information appears only in some records. Passwords, payment information, private messages, and listening history are not verified data classes for this incident.\u003C\u002Fp>\u003Cp>Bulk association of a username, avatar, and profile size with an email address can connect an artist, listener, or pseudonymous account to a private contact address. This link can make targeted phishing, fake copyright notices, collaboration offers, account-verification messages, and artist-management scams more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>SoundCloud said it activated incident response procedures after detecting unauthorized activity in an ancillary service dashboard, contained the access, and engaged independent cybersecurity specialists. The company enhanced monitoring and threat detection, reinforced identity and access controls, and audited related systems. Denial-of-service attacks also temporarily disrupted the web service after the incident was contained.\u003C\u002Fp>\u003Cp>In a January 2026 update, SoundCloud said the threat group had made demands and used email-flooding tactics against users and employees. Although the group claimed it had obtained more sensitive information, the investigation found no evidence supporting those claims. The final investigation completed in February 2026 confirmed that the taken data was limited to email addresses and information already visible on public profiles.\u003C\u002Fp>\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\u003Cp>Artists, producers, podcast publishers, label accounts, and profiles with large followings may be more visible targets for tailored messages. For people using a stage name or pseudonym, linking an email address to the profile can weaken the separation between a public identity and a private communication channel.\u003C\u002Fp>\u003Cp>Users with location data may receive fake local event, sponsorship, concert, or distribution offers, while high-visibility accounts may be targeted with verification-badge, copyright, revenue-sharing, or playlist-placement messages. Correct profile details in a message do not prove that the sender is legitimate.\u003C\u002Fp>\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\u003Cp>Password exposure was not confirmed, so this incident alone should not be presented as proof of a compromised password. Access your SoundCloud and connected email accounts through the official website or app, and do not follow links in unexpected password-reset, copyright, distribution, or collaboration messages.\u003C\u002Fp>\u003Cp>Enable multi-factor authentication on your primary email account, review active sessions and connected applications, and never share verification codes. If you receive email flooding, remember that important security alerts may be hidden among the messages; review filters and report suspicious mail.\u003C\u002Fp>\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\u003Cp>Separate the public contact address used for an artist or creator profile from your personal email address. Regularly review location, real name, and other identifying fields shown on your profile. Use a unique password for every service, a trusted password manager, and multi-factor authentication wherever available.\u003C\u002Fp>\u003Cp>The connection between an email address and a public profile identity can create a long-term targeting risk. Verify copyright, payment, distribution, advertising, and artist-management requests through a known management dashboard rather than links in messages, and regularly remove former team members' access from shared accounts.\u003C\u002Fp>\u003Ch2>Record Check and User Action\u003C\u002Fh2>\u003Cp>Search for your email address with the breach-checking tool to see whether it matches the SoundCloud record. A match shows that the email address was linked to public SoundCloud profile information in the verified dataset; it does not mean a password, financial information, or every listed field was exposed for that user.\u003C\u002Fp>","SoundCloud 2025 Data Breach (29.8 Million Reported Records)","SoundCloud 2025 Data Breach. 29.8 Million reported records are reported. Reported data: Avatars, Email addresses, Geographic locations. Review the scope…","\u002Fuploads\u002Flogo\u002Fsoundcloud_com.webp",false,{"name":7,"sector":43,"country":44,"website":10,"websiteArchiveUrl":45,"websiteStatus":45,"websiteCheckedAt":13},"Music Platform","Germany",""]