A massive data breach has shaken the music industry! Have I Been Pwned reveals that a staggering 29.8 million SoundCloud user accounts have been compromised, impacting artists and listeners alike. But wait, there's more to this story than meets the eye.
SoundCloud, the beloved platform for artists and music enthusiasts, has fallen victim to a sophisticated attack. Founded in 2007, it has grown to become a hub for over 40 million artists, offering access to an incredible 400 million tracks. However, on December 15, the company confirmed a breach after users reported being unable to access the platform, encountering 403 'Forbidden' errors.
Here's where it gets intriguing: SoundCloud's investigation revealed that a threat actor group accessed limited data, including email addresses and public profile information, for approximately 20% of its users. But they assured users that no sensitive data, such as financial or password details, was compromised.
But here's where it gets controversial: BleepingComputer's sources indicate that the breach affected around 28 million accounts, and the extortion gang ShinyHunters was responsible. The gang even attempted to extort SoundCloud, leading to a tense situation. And this is the part most people miss—the breach's impact was far-reaching, as Have I Been Pwned reported that the incident harvested email addresses, names, usernames, and profile statistics, potentially exposing millions to further cyber threats.
The aftermath of this breach is still unfolding, with ShinyHunters also claiming responsibility for ongoing voice phishing attacks targeting SSO accounts at major tech companies. This raises concerns about the security of user data and the potential for further extortion attempts.
As the story develops, one question lingers: Could this breach have been prevented, and what does it mean for the future of online security and user privacy? Share your thoughts and let's spark a conversation about the challenges of safeguarding our digital lives.