Summary
- Environment: Freshdesk
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to a Sound Radix support-agent account and evidence of access to its broader user database. [2]
Impact
Confirmed contact-data exposure and likely hashed-password exposure described by Sound Radix, with a separately measured HIBP corpus. [2]
Documented data types include:
- Names — Names of users who interacted with Sound Radix support were confirmed exposed; names in the broader database were supported by evidence Sound Radix called not conclusive. [2]
- Account credentials — Hashed passwords that Sound Radix classified as likely exposed; no hash algorithm, salt, crack status, or plaintext exposure was reported. [2]
- Contact information — Email addresses of users who interacted with support were confirmed exposed; emails in the broader database were supported by evidence Sound Radix called not conclusive. [2]
A cited record reports 292,993 records (Unique email addresses represented in HIBP’s verified, organization-submitted corpus; not a Sound Radix-confirmed number of affected people, users, support contacts, accounts, or total rows; as of 2026-03-26). [2]
HIBP said Sound Radix self-submitted the associated dataset and marked the incident record verified and not fabricated. [1][2]
Sound Radix said it did not store sensitive financial information such as credit-card numbers or bank-account details on its servers and that financial data was not exposed. [2]
Sound Radix assessed purchase history, invoices, PACE IDs, and PACE email addresses as having a low likelihood of exposure. [2]
Sound Radix said an unauthorized party accessed a support agent’s account and used it to send fraudulent emails. [2]
Timeline
Public disclosure
Date shown in Sound Radix’s first-party security update.
[2]Documented event
HIBP BreachDate and date of Sound Radix’s public update; the exact access start, detection, and containment times were not disclosed.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The incident involved Freshdesk. [2]
Sound Radix said its evidence indicated the unauthorized access extended beyond the support platform into its broader user database. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Sound Radix said it immediately secured the affected support account and implemented additional security protocols. Sound Radix said it was implementing broader security measures and continuing to monitor its systems. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
