SoundCloud confirms breach after member data stolen, VPN access disrupted
好的,我现在需要帮用户总结一篇关于SoundCloud安全事件的文章,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章提到SoundCloud最近发生了安全漏洞,导致部分用户无法访问,特别是使用VPN连接的用户遇到了403错误。攻击者窃取了一个包含用户信息的数据库,但没有涉及敏感数据如密码或财务信息。受影响的用户占20%,大约2800万账户。 接下来,SoundCloud采取了措施应对这次事件,包括与第三方安全专家合作加强安全,并阻止了未经授权的访问。不过修复过程中影响了VPN连接,恢复时间尚未公布。此外,文章还提到攻击者可能是ShinyHunters团伙,并且他们之前还攻击过PornHub。 现在我需要把这些关键点浓缩到100字以内。重点包括:安全漏洞、数据泄露、受影响人数、未涉及敏感数据、修复措施、VPN问题以及可能的攻击者。 最后,确保语言简洁明了,不使用复杂的术语,并且直接描述事件内容。 </think> SoundCloud遭遇安全漏洞,攻击者窃取包含用户信息的数据库,影响约2800万账户。平台已采取措施阻止未经授权访问,并加强安全措施。修复过程中暂时中断VPN连接,恢复时间未定。 2025-12-16 00:46:35 Author: www.bleepingcomputer.com(查看原文) 阅读量:10 收藏

SoundCloud

Audio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database containing user information.

The disclosure follows widespread reports over the past four days from users who were unable to access SoundCloud when connecting via VPN, with attempts resulting in the site displaying 403 "forbidden" errors.

In a statement shared with BleepingComputer, SoundCloud said it recently detected unauthorized activity involving an ancillary service dashboard and activated its incident response procedures.

SoundCloud acknowledged that a threat actor accessed some of its data but said the exposure was limited in scope.

"We understand that a purported threat actor group accessed certain limited data that we hold," SoundCloud told BleepingComputer.

"We have completed an investigation into the data that was impacted, and no sensitive data (such as financial or password data) has been accessed. The data involved consisted only of email addresses and information already visible on public SoundCloud profiles."

BleepingComputer has learned that the breach affects 20% of SoundCloud’s users, which, based on publicly reported user figures, could impact roughly 28 million accounts.

The company said it is confident that all unauthorized access to SoundCloud systems has been blocked and that there is no ongoing risk to the platform.

Working with third-party cybersecurity experts, the company said it took additional steps to strengthen its security, including improving monitoring and threat detection, reviewing identity and access controls, and conducting an assessment of related systems.

However, the company's response included a configuration change that disrupted VPN connectivity to the site. SoundCloud has not provided a timeline for when VPN access will be fully restored.

Following the response, SoundCloud experienced denial-of-service attacks that temporarily disabled the platform's web availability. 

While SoundCloud has not shared details about the threat actor behind the breach, BleepingComputer received a tip earlier today stating that the ShinyHunters extortion gang was responsible.

Our source said that ShinyHunters is now extorting SoundCloud after allegedly stealing a database containing information about its users.

ShinyHunters is also responsible for the PornHub data breach that was first reported today by BleepingComputer.

This is a developing story, and we will update it as more information becomes available.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/
如有侵权请联系:admin#unsafe.sh