SoundCloud ancillary-dashboard data incident

Unauthorized activity in an ancillary service dashboard that SoundCloud contained and investigated. Limited email and public-profile data confirmed by SoundCloud, with an exact HIBP corpus count.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized activity in an ancillary service dashboard that SoundCloud contained and investigated. [2]

Impact

Limited email and public-profile data confirmed by SoundCloud, with an exact HIBP corpus count. [2]

Documented data types include:

  • Contact information — Email addresses confirmed by SoundCloud and represented in HIBP’s corpus. [1][2]
  • Photographic images — Profile avatars already visible publicly, as listed by HIBP; no non-public photographic content is asserted. [1][2]
  • Names — Names already visible on public SoundCloud profiles, as listed by HIBP. [1][2]
  • Geographic location information — User country for some records, as listed by HIBP; no precise location is asserted. [1][2]
  • Usernames and account identifiers — Usernames already visible on public SoundCloud profiles, as listed by HIBP. [1][2]

A cited record reports 29,815,722 records (Unique email addresses represented in HIBP’s verified corpus; not a SoundCloud-confirmed count of affected people, accounts, users, profile rows, or total records; as of 2026-01-27). [2]

Timeline

  1. Public disclosure

    Unauthorized activity in an ancillary service dashboard that SoundCloud contained and investigated.

    [2]
  2. Documented event

    HIBP BreachDate and date of SoundCloud’s initial public notice; SoundCloud did not disclose an exact unauthorized-access start date.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

SoundCloud said the limited data affected approximately 20 percent of its users and contained no financial or password data. SoundCloud said it strengthened perimeter security, DDoS detection and mitigation, monitoring and threat detection, identity and access controls, and auditing of related systems and services. On January 13, SoundCloud said a group claiming responsibility had made demands and used email flooding to harass users, employees, and partners. After containment, SoundCloud experienced denial-of-service attacks, two of which temporarily disabled the platform’s web availability. SoundCloud detected unauthorized activity in an ancillary service dashboard, activated its incident-response protocols, and contained the activity. SoundCloud said it found no evidence supporting the group’s claims that sensitive data had been taken and was working with authorities. On February 24, SoundCloud said its third-party investigation was complete and again concluded that no sensitive data was taken. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]