SoundCloud detected unauthorized activity on an ancillary service dashboard/internal system in December 2025, leading to a data breach. The incident was publicly disclosed in January 2026. This breach involved the unauthorized mapping of email addresses to public profile data.
Confirmed data types exposed include email addresses, usernames, full names/display names, profile avatars/URLs/images, follower/following counts, and in some cases, user country or geographic location. Approximately 29.8 million user accounts were affected. No passwords, financial data, SSNs, or medical information was compromised. The types of data exposed largely matched public profile information, with the addition of email addresses. The exact number of affected individuals per US state has not been publicly confirmed.
Details can emerge later, and official notices may be delayed.