SoundCloud Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
SoundCloud disclosed a data breach on December 15, 2025, affecting 29.8 million users whose names, email addresses, geographic locations, avatars, and profile statistics were exposed. Check whether your account was included and update your password or enable additional security measures if it was.
What happened
SoundCloud stated on 15 December 2025 that it had detected unauthorised activity allowing an attacker to map publicly available profile data to email addresses. The company indicated that the resulting dataset covered roughly 29.8 million users and included 30 million unique email addresses together with names, usernames, avatars, profile statistics such as follower and following counts, and geographic locations for some accounts. After the initial discovery, the actors attempted to extort SoundCloud and subsequently released the material publicly the following month.
Details on the precise method of initial access, the duration of the activity, and the full scope of any additional systems accessed remain undisclosed in the available reporting.
How a breach like this happens
Incidents involving the linkage of public profile data to internal identifiers often begin with an attacker obtaining limited access to a platform’s backend or user database. Once inside, an adversary can query or export records that pair visible usernames with stored email addresses. Such access may result from compromised credentials, misconfigured permissions, or vulnerabilities in application programming interfaces that return user information.
After extraction, the collected data are frequently used for extortion or sold on underground forums. Public release can follow if demands are not met, increasing the long-term availability of the information.
About SoundCloud
SoundCloud operates a large audio-distribution platform used by independent creators and listeners worldwide. Like other services in the streaming and social-media sector, it maintains user accounts that include contact details, profile images, and activity metrics. These records are necessary for account management, notifications, and content discovery features.
Because the platform holds direct identifiers such as email addresses alongside publicly visible usernames, any exposure can combine information that was previously fragmented across separate sources.
What was likely exposed
The information named in SoundCloud’s announcement includes email addresses, names, usernames, avatars, follower and following counts, and geographic locations for some users. The company reported approximately 30 million unique email addresses associated with the 29.8 million affected accounts.
Whether additional fields such as passwords, payment details, or private messages were accessed has not been disclosed. Organisations of this type commonly store further account metadata, but the exact contents of the released dataset beyond the listed categories remain unconfirmed.
What's at stake
Exposed email addresses combined with usernames and locations can facilitate targeted phishing campaigns and unwanted contact. When profile statistics are also available, the data may be used to build more convincing impersonation attempts or to enrich existing datasets sold for marketing or fraud purposes.
For the organisation, the incident adds to the operational burden of notifying users, investigating the access method, and managing reputational effects. For individuals, the primary concern is the persistence of email addresses in circulation, which can increase exposure to unsolicited messages over time.
What to do if you're exposed
Users who believe their information may have been included should review recent login activity on their SoundCloud account and any linked services that share the same email address. Enabling or confirming multi-factor authentication on those accounts reduces the value of the exposed email for further compromise.
Monitoring for unusual messages and avoiding reuse of the exposed email for sensitive registrations are standard precautions. Readers can run a free exposure scan of their email address against known breach datasets to determine whether their information appears in this or other publicly reported incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Pass'Sport Data Breach (2025)APOIA.se Data Breach (2025)Under Armour Data Breach (2025)CodeStepByStep Data Breach (2025)Latest breaches
Read GalaxyWarden’s full analysis of the SoundCloud Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.