SoundCloud Data Breach Exposes Nearly 30M User Accounts

SoundCloud Data Breach Exposes Nearly 30M User Accounts

SoundCloud Data Breach Exposes Nearly 30M User Accounts

Image: appshunter.io (Unsplash)

A SoundCloud breach affecting 29.8 million accounts exposed email addresses and profile data, increasing phishing risks.

Written By
Kezia Jungco
Kezia Jungco
Jan 30, 2026

If you’ve ever had a SoundCloud account, now might be a good time to double-check your security settings.

Reports indicate that the music streaming platform suffered a major data breach, exposing information tied to nearly 30 million users. The incident, first detected in December 2025, reportedly enabled attackers to link private email addresses with public profile details, such as usernames and follower counts.

While SoundCloud passwords, payment data, and private messages were not included in the breach, the exposure still poses risks. Cybersecurity experts warn that it can increase phishing, impersonation, and targeted scams for both everyday listeners and creators.

What happened in the SoundCloud breach

SoundCloud was reported to have discovered unauthorized activity in December 2025 that enabled attackers to map private email addresses to public profile information at scale.

According to Centraleyes, the breach didn’t involve a direct break-in to SoundCloud’s main user database. Instead, attackers allegedly gained access to an internal system and used it to connect private email addresses with public profile information. This allowed them to build a large dataset linking user identities and contact details at scale,” Centraleyes noted.

The breach later appeared in Have I Been Pwned, which listed approximately 29.8 million affected accounts and confirmed the incident was added to its database in January 2026.

What information was exposed

According to Have I Been Pwned, the compromised dataset included unique email addresses and publicly available profile information.

The exposed data included names, usernames, avatars, follower and following counts, and in some cases, geographic location details. After allegedly attempting to extort SoundCloud, the attackers publicly released the data the following month.

Have I Been Pwned noted that passwords, payment information, and private messages were not part of the breach? That reduces the likelihood of direct account takeover on SoundCloud itself, but the privacy impact is still significant.

Centraleyes also emphasized that linking email addresses with profile identities can make it easier for attackers to craft convincing phishing emails that appear legitimate. “This can affect other services you use, especially if you reuse passwords,” Centraleyes added.

Advertisement

Must-read security coverage

What users should know

Even when passwords are not exposed, breaches involving email addresses can still create security problems. Attackers often use leaked emails to launch phishing campaigns or test credentials across other platforms where people may reuse passwords.

This kind of exposure also makes it easier for scammers to send convincing messages that appear tied to your SoundCloud identity, especially for artists, podcasters, and creators with public audiences.

Have I Been Pwned recommended that users change reused passwords immediately and enable two-factor authentication wherever possible. Users can also check if their email has been compromised in a data breach by searching the Have I Been Pwned website.

Further reading: Want to avoid a data breach? Learn how to effectively manage a data breach with our in-depth guide.

Kezia Jungco

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.