Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsShinyHunters Leak Alleged Data of Millions From SoundCloud, Crunchbase and Betterment
ShinyHunters Leak Alleged Data of Millions From SoundCloud, Crunchbase and Betterment
Cybersecurity

ShinyHunters Leak Alleged Data of Millions From SoundCloud, Crunchbase and Betterment

•January 23, 2026
0
HackRead
HackRead•Jan 23, 2026

Companies Mentioned

Crunchbase

Crunchbase

SoundCloud

SoundCloud

Betterment

Betterment

Okta

Okta

OKTA

LinkedIn

LinkedIn

Why It Matters

The alleged exposure of millions of user records heightens privacy risks and underscores the growing threat of coordinated extortion‑leak operations across the tech sector.

Key Takeaways

  • •ShinyHunters posted alleged dumps for three firms on .onion site.
  • •Leak claims 35‑36 million SoundCloud accounts affected.
  • •Extortion attempts were denied before data was released.
  • •Group may also run Okta SSO vishing campaign.
  • •Data circulating on French and Russian cyber‑crime forums.

Pulse Analysis

The resurgence of ShinyHunters illustrates how cyber‑crime groups leverage failed extortion attempts to weaponize data leaks. By publishing partial dumps of high‑profile platforms such as SoundCloud, Crunchbase and Betterment on a dedicated .onion portal, the actors aim to pressure victims into payment while simultaneously profiting from the sale of credentials on underground markets. This tactic builds on the December 2025 SoundCloud breach, where roughly 20 percent of its 175‑million user base was compromised, suggesting the group may have harvested data from that incident or similar sources.

Security analysts are closely watching the alleged link between ShinyHunters and an Okta single‑sign‑on (SSO) vishing campaign. Okta’s advisory warns that attackers are phishing users for authentication tokens, a method that can grant attackers unfettered access to corporate environments. If the same threat actor controls both the data dumps and the vishing operation, it signals a more sophisticated supply‑chain threat where credential theft and data exposure are coordinated to maximize impact on enterprises relying on cloud identity services.

For organizations, the key takeaway is proactive threat hunting across dark‑web forums and rapid verification of any claimed data exposure. Companies should enforce multi‑factor authentication, monitor for anomalous login attempts, and engage incident‑response teams immediately upon suspicion of a breach. Regularly updating security awareness training to include vishing scenarios can also reduce the success rate of social‑engineering attacks tied to identity platforms like Okta.

ShinyHunters Leak Alleged Data of Millions From SoundCloud, Crunchbase and Betterment

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...