リーディングビュー

SoundCloud Data Breach Impacts 29.8 Million Accounts

🤖 AI Summary

**サマリー(日本語)**

- **被害規模**:SoundCloudで約2,980万件(全ユーザーの約20%)のアカウント情報が流出。
- **流出データ**:メールアドレスと、公開プロフィールにすでに掲載されていた情報のみ。パスワードや金融情報は含まれなかった。
- **発覚と対応**:不正アクセスは12月15日に確認され、VPN経由で「403 Forbidden」エラーが多数報告されたことから、SoundCloudはインシデント対応手順を発動。調査の結果、機密データは取得されていないことを公表。
- **攻撃者**:ShinyHuntersという身代金要求を行うハッカー集団が関与。攻撃後、同集団はSoundCloud自体やユーザー、従業員、パートナーに対してメール大量送信による嫌がらせと身代金要求を実施。
- **公式声明**:1月15日のアップデートで、脅威アクターが「要求を行い、メールでの嫌がらせを行った」ことを認め、被害はメールアドレスと公開情報に限定されると再確認した。

**要点**:パスワードや金銭情報は漏えていないものの、膨大な数のメールアドレスが外部に流出し、ShinyHuntersによる extortion(身代金要求)とメール嫌がらせが問題となった。SoundCloudはインシデント対応を行い、被害内容を公表している。
A data breach at SoundCloud exposed information tied to 29.8 million user accounts, according to Have I Been Pwned. While SoundCloud says no passwords or financial data were accessed, attackers mapped email addresses to public profile data and later attempted extortion. BleepingComputer reports: The company confirmed the breach on December 15, following widespread reports from users who were unable to access SoundCloud and saw 403 "Forbidden" errors when connecting via VPN. SoundCloud told BleepingComputer at the time that it had activated its incident response procedures after detecting unauthorized activity involving an ancillary service dashboard. "We understand that a purported threat actor group accessed certain limited data that we hold," SoundCloud said. "We have completed an investigation into the data that was impacted, and no sensitive data (such as financial or password data) has been accessed. The data involved consisted only of email addresses and information already visible on public SoundCloud profiles." While SoundCloud didn't provide further details regarding the incident, BleepingComputer learned that the breach affected 20% of all SoundCloud users, roughly 28 million accounts based on publicly reported user figures (SoundCloud later published a security notice confirming the information provided by BleepingComputer's sources). After the breach, BleepingComputer also learned that the ShinyHunters extortion gang was responsible for the attack, with sources saying that the threat group was also attempting to extort SoundCloud. This was confirmed by SoundCloud in a January 15 update, which said the threat actors had "made demands and deployed email flooding tactics to harass users, employees, and partners."

Read more of this story at Slashdot.

  •  
❌