Live data from Hacker News

SoundCloud Data Breach Now on HaveIBeenPwned

haveibeenpwned.com

31–40 of 113 posts

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#31

> the impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the user’s country

Importantly, 20% of the total userbase it seems: > In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform. The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the…

Also, never give out a direct email address, always an alias.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#33
post #20

"The data involved consisted only of email addresses and information already visible on public SoundCloud profiles". So they've scraped public data. Why care?

Maybe the two public data points weren't connected before? I don't use SoundCloud, but if profiles didn't have contact information like Email Address on them then it could be meaningful to now connect those two dots. Like, 'Hey look, Person A, who is known to use email address X, kept Lost Prophets as one of their liked artists even after 2013!'

You are 100% correct based on article. Not good that you're gray, and your parent of "who cares it was already available and scraped" is the top comment.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#35
post #20

"The data involved consisted only of email addresses and information already visible on public SoundCloud profiles". So they've scraped public data. Why care?

Maybe the two public data points weren't connected before? I don't use SoundCloud, but if profiles didn't have contact information like Email Address on them then it could be meaningful to now connect those two dots. Like, 'Hey look, Person A, who is known to use email address X, kept Lost Prophets as one of their liked artists even after 2013!'

But, why care? (Yes, we can “care” that there was a leak - but… why worry? what new risk exists today that didn’t yesterday?)

The data in the leak (other than follower count, etc) was already available for purchase from Zoominfo, 8sense, or a variety of other data brokers or other legal marketplaces for PII.

I suppose the risk now is that the data is freely available and no longer behind a data broker’s paywall?

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#36
post #20

"The data involved consisted only of email addresses and information already visible on public SoundCloud profiles". So they've scraped public data. Why care?

Maybe the two public data points weren't connected before? I don't use SoundCloud, but if profiles didn't have contact information like Email Address on them then it could be meaningful to now connect those two dots. Like, 'Hey look, Person A, who is known to use email address X, kept Lost Prophets as one of their liked artists even after 2013!'

Yeah or this: https://news.ycombinator.com/item?id=26386418

SoundCloud is a weird place, people in entertainment have certain strong incentives. They figured out who I am, figured out all the email addresses I have, jacked the account attached to my SoundCloud, stole my account. I still to this day, don't know how they pwned my email (tfa was on but it didn't trigger suspicious activity it let them login without triggering it, no clue how they got the password either and the password is secure enough that it's too hard to brute force, and it's not in a pwned db). Based on what was in my soundcloud inbox when I got access again, someone paid a fair amount to have this done... and now I have to go change my email again I suppose.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#37
post #20

"The data involved consisted only of email addresses and information already visible on public SoundCloud profiles". So they've scraped public data. Why care?

Hackers stole information of 29.8M accounts (~20% of users). SoundCloud is downplaying the data beyond email address as "publicly available", but the data wasn't scraped. "Profile statistics" aren't public either. Their main response[0], seems to focus on passwords and payment details being the only risky data. They even imply email addresses are public.

> no sensitive data was taken in the incident.The data involved consisted only of email addresses and information already visible on public SoundCloud profiles (not financial or password data)

[0]: https://soundcloud.com/playbook-articles/protecting-our-user...

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#38

Earlier quoted context omitted.

A former paying user is not a customer. If you don't pay, why should you receive service? I buy a pizza at this pizza shop every week, but I still don't get free ones. SoundCloud is European, so most of the dark patterns used by American companies to offer "free" service are not available to them, and they are required by law to actually delete data instead of pretending to delete it.

> I buy a pizza at this pizza shop every week, but I still don't get free ones. Do they take the leftovers from your fridge when you stop buying?

If I haven't bought pizza for two months, they use their magical ray, reach into my fridge and turn the leftovers into mold.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#39

A lot of "rap gods" are about to be exposed as "Kevin" from suburbia.

Lil B is probably fine, but he is the biggest name I recall coming out of SoundCloud. He blew up all over the 2010s, he was the Kanye of Cloudrap too because he took dressing styles and changed it all up similar to Kanye.

There's a few big names: Post Malone, Billie Eilish, Lil Nas X, Khalid, Bad Bunny

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#40

Earlier quoted context omitted.

They first hide your songs and as time goes on they start threaten to delete your songs if you dont pay

What should they do instead? spend money continuously holding your music on disk forever even though you aren't paying them for the service? Sounds like they are being cool about it by keeping it around for a while and warning you before deleting it.

The marketing move of offering an unlimited plan reveals that storage and traffic are not that expensive and someone made a choice that light users will subsidize heavy users. With that, hiding your data from you and subsequently deleting it, at least without first encouraging you to download it within some post-downgrade grace period, would be a choice, not necessity, and is user-hostile.

If it is an actual necessity—a service chose to market an unlimited plan to attract more users, and then realized they are losing money on storage and traffic so much that they would unapologetically burn bridges with existing users who showed themselves as willing to pay (who maybe needed to downgrade temporarily for whatever reason) with the above move—and yet their strategy is apparently to keep offering that plan (in hopes to turn things around with more light users joining?), I would question whether that service has serious issues with even medium term planning.

Post reply on HN