---
title: "Sound Radix support-platform and user-database incident"
description: "Evidence-backed account of Sound Radix support-platform and user-database incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/sound-radix-support-user-database-incident-2026"
markdown_url: "https://www.ally.security/incidents/sound-radix-support-user-database-incident-2026.md"
stix_url: "https://www.ally.security/incidents/sound-radix-support-user-database-incident-2026/stix.json"
---

# Sound Radix support-platform and user-database incident

Unauthorized access to a Sound Radix support-agent account and evidence of access to its broader user database. Confirmed contact-data exposure and likely hashed-password exposure described by Sound Radix, with a separately measured HIBP corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Freshdesk
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to a [Sound Radix](https://www.soundradix.com/) support-agent account and evidence of access to its broader user database. [2](#source-2)

## Impact

Confirmed contact-data exposure and likely hashed-password exposure described by Sound Radix, with a separately measured HIBP corpus. [2](#source-2)

Documented data types include:

- Names — Names of users who interacted with Sound Radix support were confirmed exposed; names in the broader database were supported by evidence Sound Radix called not conclusive. [2](#source-2)
- Account credentials — Hashed passwords that Sound Radix classified as likely exposed; no hash algorithm, salt, crack status, or plaintext exposure was reported. [2](#source-2)
- Contact information — Email addresses of users who interacted with support were confirmed exposed; emails in the broader database were supported by evidence Sound Radix called not conclusive. [2](#source-2)

A cited record reports 292,993 records (Unique email addresses represented in HIBP's verified, organization-submitted corpus; not a Sound Radix-confirmed number of affected people, users, support contacts, accounts, or total rows; as of 2026-03-26). [2](#source-2)

HIBP said Sound Radix self-submitted the associated dataset and marked the incident record verified and not fabricated. [1](#source-1) [2](#source-2)

Sound Radix said it did not store sensitive financial information such as credit-card numbers or bank-account details on its servers and that financial data was not exposed. [2](#source-2)

Sound Radix assessed purchase history, invoices, PACE IDs, and PACE email addresses as having a low likelihood of exposure. [2](#source-2)

Sound Radix said an unauthorized party accessed a support agent's account and used it to send fraudulent emails. [2](#source-2)

## Timeline

### March 25, 2026 — Public disclosure

Date shown in Sound Radix's first-party security update. [2](#source-2)

### March 25, 2026 — Documented event

HIBP BreachDate and date of Sound Radix's public update; the exact access start, detection, and containment times were not disclosed. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The incident involved Freshdesk. [2](#source-2)

Sound Radix said its evidence indicated the unauthorized access extended beyond the support platform into its broader user database. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Sound Radix said it immediately secured the affected support account and implemented additional security protocols. Sound Radix said it was implementing broader security measures and continuing to monitor its systems. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/sound-radix-support-user-database-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Sound Radix breach record

advisory · Have I Been Pwned · Mar 26, 2026

<https://haveibeenpwned.com/api/v3/breach/SoundRadix>

<a id="source-2"></a>

### Security Update: Important Information Regarding Your Sound Radix Account

official · Sound Radix · Mar 25, 2026

<https://support.soundradix.com/support/solutions/articles/5000900043>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Data Category · 95% confidence · current**  
   Sound Radix support and user data exposure: Names
2. **Resulted In · 100% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Sound Radix said it immediately secured the affected support account and implemented additional security protocols.
3. **Affected Organization · 100% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Sound Radix
4. **Used Product · 100% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Freshdesk
5. **Exposed Record Count · 100% confidence · current**  
   Sound Radix support and user data exposure: 292,993 record
6. **Resulted In · 100% confidence · current**  
   Sound Radix support and user data exposure: HIBP said Sound Radix self-submitted the associated dataset and marked the breach record verified and not fabricated.
7. **Resulted In · 100% confidence · current**  
   Sound Radix support and user data exposure: Sound Radix said it did not store sensitive financial information such as credit-card numbers or bank-account details on its servers and that financial data was not exposed.
8. **Resulted In · 95% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Sound Radix support and user data exposure
9. **Resulted In · 100% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Sound Radix said it was implementing broader security measures and continuing to monitor its systems.
10. **Resulted In · 90% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Sound Radix said its evidence indicated the unauthorized access extended beyond the support platform into its broader user database.
11. **Exposed Data Category · 75% confidence · current**  
   Sound Radix support and user data exposure: Account credentials
12. **Resulted In · 80% confidence · current**  
   Sound Radix support and user data exposure: Sound Radix assessed purchase history, invoices, PACE IDs, and PACE email addresses as having a low likelihood of exposure.
13. **Exposed Data Category · 95% confidence · current**  
   Sound Radix support and user data exposure: Contact information
14. **Resulted In · 100% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: Sound Radix said an unauthorized party accessed a support agent's account and used it to send fraudulent emails.
15. **Disclosed At · 100% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: 2026-03-25
16. **Occurred At · 85% confidence · current**  
   March 2026 Sound Radix unauthorized-access incident: 2026-03-25

</details>
