Data leak

SoundCloud Data Breach - ShinyHunters Vishing (29.8M Accounts)

πŸ“… 2025-12-15
Primary Source β†—

Incident Details

In December 2025, ShinyHunters breached SoundCloud via vishing β€” attackers convinced employees to provide access to an ancillary service dashboard. SoundCloud confirmed the breach on December 15, 2025. After the company declined to pay ransom, ShinyHunters began leaking data on January 22, 2026, via Telegram and .onion links. The breach affected approximately 29.8 million accounts, roughly 20% of SoundCloud’s user base. Exposed data included names, email addresses, usernames, avatars, follower/following counts, and select users’ countries. Passwords, payment card numbers, and financial information were not accessed. Have I Been Pwned indexed the dataset. The breach is part of ShinyHunters’ broader 2025–2026 campaign targeting companies via Salesforce/Okta vishing, alongside Qantas, Vietnam Airlines, CarGurus, Crunchbase, Betterment, and dozens of others.

Technical Details

Initial Attack Vector
ShinyHunters used vishing (voice phishing) to trick SoundCloud employees into providing access credentials to an ancillary service dashboard rather than the company's core production systems

Timeline

  1. 2025-12-15 Breach occurred
  2. 2025-12-15 Publicly disclosed
  3. 2025-12-15 Customers notified