Millions impacted by PornHub, SoundCloud data breaches
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”这样的开头。首先,我需要通读整篇文章,理解主要信息。 文章讲的是两个平台,SoundCloud和PornHub最近都遭遇了网络安全入侵。PornHub被Mixpanel的数据泄露影响,黑客通过Mixpanel获取了一些用户的分析数据,但没有涉及到支付信息。而SoundCloud则检测到辅助服务面板的未经授权活动,导致部分用户数据泄露,但同样没有敏感信息被访问。 接下来,我需要把这些信息浓缩到100字以内。要注意关键点:两个平台、数据泄露、受影响的数据类型、以及是否有敏感信息泄露。 然后,检查是否有遗漏的重要细节。比如,Mixpanel在11月27日报告了安全事件,并且提到了ShinyHunters这个黑客组织可能参与其中。不过这些可能超出了100字的限制,所以可能需要简化。 最后,确保语言简洁明了,直接描述事件即可。 </think> 音乐分享平台SoundCloud和成人网站PornHub近期均报告遭受网络安全入侵。PornHub因数据服务提供商Mixpanel的漏洞导致部分用户数据外泄;SoundCloud检测到辅助服务面板的未经授权访问。两起事件均未涉及敏感支付或密码信息。 2025-12-18 02:1:18 Author: therecord.media(查看原文) 阅读量:9 收藏

Music sharing platform Soundcloud and pornography giant PornHub both warned customers this week of recent cybersecurity intrusions that gave hackers access to internal data. 

PornHub, which is owned by Canada-based Ethical Capital Partners, sent emails out to many users and published a statement warning that it was affected by a recent breach of data analytics service provider Mixpanel. 

The hackers used their access through Mixpanel to “extract a limited set of analytics events for some users,” PornHub said in a statement. The company said its Pornhub Premium systems were not breached and no payment details or financial information was exposed. 

When reached for comment, PornHub declined to say how many users were affected and what information was stolen. Several news outlets reported on a prominent group of hackers allegedly extorting PornHub with threats of leaking stolen data but their claims could not be verified. 

The company said it is working with law enforcement and Mixpanel to investigate the issue. In comments to Reuters, Mixpanel denied that it was at fault for the data that was allegedly stolen from PornHub. 

Mixpanel itself reported a security incident on November 27, with CEO Jen Taylor writing that the cyberattack was first discovered on November 8. The company shared few details about the breach, only writing that it was the victim of a “smishing” campaign and has contacted all of the customers affected by the attacks. 

OpenAI came forward one day earlier as one of the Mixpanel customers impacted by the breach. OpenAI uses Mixpanel for web analytics and said some of its API users had data stolen as part of the incident. 

“On November 9, 2025, Mixpanel became aware of an attacker that gained unauthorized access to part of their systems and exported a dataset containing limited customer identifiable information and analytics information,” OpenAI said in a statement on November 26. “Mixpanel notified OpenAI that they were investigating, and on November 25, 2025, they shared the affected dataset with us.”

The information stolen from OpenAI included names, email addresses, location, operating system and other technical information on API users. OpenAI says it removed Mixpanel from its production services and is in the process of notifying impacted organizations. 

Soundcloud breached

On Monday, music sharing platform Soundcloud also came forward to warn customers about a similar data breach.

While SoundCloud did not name Mixpanel, the company said it “recently detected unauthorized activity in an ancillary service dashboard.”

SoundCloud’s IT team attempted to contain the activity and hired cybersecurity experts to handle the response. But when they tried to limit the hackers’ access, the site “experienced denial of service attacks, two of which were able to temporarily disable our platform's availability on the web only.”

“We understand that a purported threat actor group accessed certain limited data that we hold. We have completed an investigation into the data that was impacted, and no sensitive data (such as financial or password data) has been accessed,” the company said. 

“The data involved consisted only of email addresses and information already visible on public SoundCloud profiles and affected approximately 20% of SoundCloud users. We are confident that any access to SoundCloud data has been curtailed.”

SoundCloud has about 200 million users, meaning the incident likely impacted about 40 million customers. 

The company noted that some of the security changes made over the last week have caused users with VPNs to experience connectivity issues. 

BleepingComputer spoke with members of a prominent cybercriminal group called ShinyHunters that allegedly took credit for the Mixpanel attacks. If accurate, the claims would represent yet another high-profile hacking campaign launched by members of the group this year. 

Members of the group previously breached customers of Salesforce and exploited loopholes in a related platform that allowed them to harass and extort companies in aviation, insurance and retail throughout the summer.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/millions-impacted-pornhub-soundcloud-breaches
如有侵权请联系:admin#unsafe.sh