---
title: "SoundCloud ancillary-dashboard data incident"
description: "Evidence-backed account of SoundCloud ancillary-dashboard data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/soundcloud-ancillary-dashboard-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/soundcloud-ancillary-dashboard-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/soundcloud-ancillary-dashboard-data-incident-2025/stix.json"
---

# SoundCloud ancillary-dashboard data incident

Unauthorized activity in an ancillary service dashboard that SoundCloud contained and investigated. Limited email and public-profile data confirmed by SoundCloud, with an exact HIBP corpus count.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized activity in an ancillary service dashboard that [SoundCloud](https://soundcloud.com/) contained and investigated. [2](#source-2)

## Impact

Limited email and public-profile data confirmed by SoundCloud, with an exact HIBP corpus count. [2](#source-2)

Documented data types include:

- Contact information — Email addresses confirmed by SoundCloud and represented in HIBP's corpus. [1](#source-1) [2](#source-2)
- Photographic images — Profile avatars already visible publicly, as listed by HIBP; no non-public photographic content is asserted. [1](#source-1) [2](#source-2)
- Names — Names already visible on public SoundCloud profiles, as listed by HIBP. [1](#source-1) [2](#source-2)
- Geographic location information — User country for some records, as listed by HIBP; no precise location is asserted. [1](#source-1) [2](#source-2)
- Usernames and account identifiers — Usernames already visible on public SoundCloud profiles, as listed by HIBP. [1](#source-1) [2](#source-2)

A cited record reports 29,815,722 records (Unique email addresses represented in HIBP's verified corpus; not a SoundCloud-confirmed count of affected people, accounts, users, profile rows, or total records; as of 2026-01-27). [2](#source-2)

## Timeline

### December 15, 2025 — Public disclosure

Unauthorized activity in an ancillary service dashboard that SoundCloud contained and investigated. [2](#source-2)

### December 15, 2025 — Documented event

HIBP BreachDate and date of SoundCloud's initial public notice; SoundCloud did not disclose an exact unauthorized-access start date. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

SoundCloud said the limited data affected approximately 20 percent of its users and contained no financial or password data. SoundCloud said it strengthened perimeter security, DDoS detection and mitigation, monitoring and threat detection, identity and access controls, and auditing of related systems and services. On January 13, SoundCloud said a group claiming responsibility had made demands and used email flooding to harass users, employees, and partners. After containment, SoundCloud experienced denial-of-service attacks, two of which temporarily disabled the platform's web availability. SoundCloud detected unauthorized activity in an ancillary service dashboard, activated its incident-response protocols, and contained the activity. SoundCloud said it found no evidence supporting the group's claims that sensitive data had been taken and was working with authorities. On February 24, SoundCloud said its third-party investigation was complete and again concluded that no sensitive data was taken. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/soundcloud-ancillary-dashboard-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### SoundCloud breach record

advisory · Have I Been Pwned · Jan 27, 2026

<https://haveibeenpwned.com/api/v3/breach/SoundCloud>

<a id="source-2"></a>

### Protecting Our Users and Our Service

official · SoundCloud · Dec 15, 2025

<https://soundcloud.com/playbook-articles/protecting-our-users-and-our-service>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: SoundCloud email and public-profile data exposure
2. **Affected Organization · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: SoundCloud
3. **Resulted In · 100% confidence · current**  
   SoundCloud email and public-profile data exposure: SoundCloud said the limited data affected approximately 20 percent of its users and contained no financial or password data.
4. **Disclosed At · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: 2025-12-15
5. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: SoundCloud said it strengthened perimeter security, DDoS detection and mitigation, monitoring and threat detection, identity and access controls, and auditing of related systems and services.
6. **Exposed Data Category · 100% confidence · current**  
   SoundCloud email and public-profile data exposure: Contact information
7. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: On January 13, SoundCloud said a group claiming responsibility had made demands and used email flooding to harass users, employees, and partners.
8. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: After containment, SoundCloud experienced denial-of-service attacks, two of which temporarily disabled the platform's web availability.
9. **Exposed Data Category · 95% confidence · current**  
   SoundCloud email and public-profile data exposure: Photographic images
10. **Exposed Record Count · 100% confidence · current**  
   SoundCloud email and public-profile data exposure: 29,815,722 record
11. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: SoundCloud detected unauthorized activity in an ancillary service dashboard, activated its incident-response protocols, and contained the activity.
12. **Exposed Data Category · 95% confidence · current**  
   SoundCloud email and public-profile data exposure: Names
13. **Exposed Data Category · 90% confidence · current**  
   SoundCloud email and public-profile data exposure: Geographic location information
14. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: SoundCloud said it found no evidence supporting the group's claims that sensitive data had been taken and was working with authorities.
15. **Occurred At · 85% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: 2025-12-15
16. **Resulted In · 100% confidence · current**  
   December 2025 SoundCloud ancillary-dashboard incident: On February 24, SoundCloud said its third-party investigation was complete and again concluded that no sensitive data was taken.
17. **Exposed Data Category · 95% confidence · current**  
   SoundCloud email and public-profile data exposure: Usernames and account identifiers

</details>
