SoundCloud Breach: 29.8M Accounts Exposed
In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform . The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, use...
Overview
In December 2025, SoundCloud detected unauthorized activity on its systems. An attacker was able to link publicly available user profile information-such as usernames and follower counts-to the private email addresses associated with those accounts. This breach impacted data for nearly 30 million users. After SoundCloud did not comply with an extortion attempt, the attackers publicly released the stolen data the following month. If you have or had a SoundCloud account, your personal information may now be circulating online.
What Was Exposed
The stolen dataset is significant because it connects different pieces of your digital identity. The core exposed elements include:
- Email Addresses: Your primary account identifier.
- Usernames & Names: Your public or display name on the platform.
- Profile Data: This includes avatars, follower/following counts, and, for some users, their country.
The critical risk lies in the linkage. While some data was public on profiles, the breach attached it directly to your private email, creating a more valuable package for misuse.
Potential Impact
Having your email, name, and username exposed together significantly increases your risk of targeted cyber attacks.
- Phishing & Spam: You will likely see a sharp increase in sophisticated phishing emails. Attackers can use your real name and reference “SoundCloud” to make scam messages appear legitimate, tricking you into revealing passwords or financial data.
- Credential Stuffing: Cybercriminals will use the exposed email addresses and passwords (if you reused your SoundCloud password elsewhere) to attempt to log into your other online accounts, such as banking, social media, or shopping sites.
- Identity Theft & Social Engineering: The combined information provides a foundation for identity theft. Scammers can use these personal details to impersonate you or make their attempts to manipulate you or your contacts seem more credible.
Recommendations
Take these steps immediately to secure your accounts and personal information.
- Change Your SoundCloud Password: Immediately update to a strong, unique password on SoundCloud. Do not reuse this password on any other website or service.
- Enable Two-Factor Authentication (2FA): Activate 2FA on your SoundCloud account and any other important account (especially email, banking, and social media) that offers it. This adds a critical second layer of security.
- Beware of Targeted Phishing: Be extremely cautious with all emails, even those that appear to come from SoundCloud or other trusted services. Do not click on links or open attachments in unsolicited messages. Verify communications by going directly to the official website.
- Audit Your Accounts: Review your other online accounts, especially those using the same email address exposed here. Ensure you are using unique passwords for each.
- Consider a Password Manager: Using a password manager is the most effective way to create and manage strong, unique passwords for every account you own.
How to Check If You’re Affected
The breach has been verified and added to the website Have I Been Pwned, a free resource that tracks data breaches. To check if your information was involved:
- Go to https://haveibeenpwned.com
- Enter the email address you used for your SoundCloud account.
- The site will show you if that email address appears in the SoundCloud breach and any other known breaches.
If you are affected, follow the recommendations above. Even if you are not listed, it remains a best practice to use unique passwords and enable 2FA on all critical accounts.
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt . Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later pu...
In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt...
In March 2026, the personal development and achievement media brand SUCCESS suffered a data breach . The incident exposed 250k unique email addresses along with names, IP addresses, phone numbers and, for a limited number of staff members, bcrypt password hashes. The data also included orders contai...
In March 2026, a breach of one of the many iterations of the BreachForums hacking forum known as "Version 5" was publicly disclosed . The incident exposed 340k unique email addresses along with usernames and argon2 password hashes.