Back Techtimes Ariana Grande Sues Hackers Who Exploited Her Collaborators to Steal Unreleased Music
According to the complaint she filed this week, hackers never broke into Ariana Grande's own accounts. They broke into her photographer's Dropbox instead.
A California state court complaint filed Monday in Los Angeles Superior Court lays out how anonymous defendants allegedly bypassed the pop star herself and spent 15 years systematically targeting the photographers, producers, and digital technicians in her professional orbit — people with regular access to unreleased material and, in many cases, far less security than the artist they worked for. With the artist's eighth studio album petal due Friday, July 31 , the timing of the suit is pointed: Grande is going on record that stolen pre-release content has disrupted her creative process for more than a decade, and she wants to know who is responsible.
The lawsuit names "John Doe 1" and "John Does 2 through 100" as defendants — a standard placeholder structure for civil cases where the identities of defendants are not yet known — and accuses them of invasion of privacy, violation of California's Comprehensive Computer Data Access and Fraud Act (Penal Code § 502), and conversion , the civil-law equivalent of theft. Grande is demanding a jury trial.
The technical picture the complaint draws is not one of a celebrity being hacked. It is one of a supply chain being picked apart.
In 2019, according to the complaint, the defendants obtained login credentials for a Dropbox account belonging to a photographer who had previously worked with Grande, and downloaded unreleased photos stored there. The following year, they allegedly hacked a producer's mobile device and accessed still-in-production masters, demos, and footage from recording sessions. In 2023 alone, the complaint alleges that 45 of Grande's unreleased songs were stolen and subsequently leaked . The complaint further states that "since her music debut in 2011, hundreds of similar leaks have taken place ."
The 2024 incidents described in the suit add a social engineering layer. Defendants allegedly created a fake Gmail account and registered a domain name designed to impersonate one of Grande's photographers , then used that identity to persuade a digital technician into transmitting unreleased photos — a business email compromise (BEC) attack dressed up as routine professional correspondence. The complaint also identifies two additional phishing incidents in January and February 2024 .
The defendants allegedly sold the stolen content through third-party payment services including PayPal and Cash App before buyers published it across public platforms.
This pattern — bypassing the well-protected principal and compromising peripheral collaborators — is a textbook supply-chain attack. Modern pop music production involves dozens of people who routinely handle sensitive pre-release material: photographers, mixing engineers, co-writers, producers, stylists, assistants. Each of them represents a point of access with no centralized security governance. The more prominent an artist, the more collaborators that orbit them, and the larger the distributed attack surface becomes.
A central strategic goal of the complaint is not damages — it is discovery. Because the defendants are anonymous, Grande's legal team is betting that the litigation process itself will generate the tools needed to identify them.
"Ariana Grande is going to subpoena — meaning ask for information from Internet Service Providers, essentially from any tech company who could have information who she thinks have allegedly committed these wrongs against her," CBS News legal contributor Jessica Levinson explained . The complaint explicitly states that the action is intended "to uncover the identities of these currently unknown and unscrupulous individuals in order to hold them accountable for their invasive and reprehensible conduct."
The "John Doe" structure is a well-established tool for exactly this scenario. Once a court grants discovery, Grande's attorneys can compel Dropbox, Google, ISPs, PayPal, and Cash App to turn over account data, IP addresses, and transaction records associated with the alleged breaches and sales. The goal is to amend the complaint with real names once those records surface. If PayPal and Cash App transaction records survive and can be subpoenaed, they may prove especially useful — financial payment rails leave trails that pseudonymous online handles do not.
The complaint also seeks an order requiring the defendants to return her stolen content and cease further distribution, in addition to unspecified damages.
Grande's suit lands inside a broader legal and criminal pressure campaign on the underground market for stolen music that has accelerated sharply since 2024.
The most prominent prosecution to date involved Noah Urban, a then-20-year-old from Palm Coast, Florida, who operated online as "King Bob" and was a core member of the cybercrime collective Scattered Spider. Sentenced on August 20, 2025 to 10 years in federal prison and ordered to pay $13 million in restitution to 59 victims , Urban had gained notoriety in fan communities for acquiring and leaking unreleased tracks from Grande, Playboi Carti, Lil Uzi Vert, and others. Researchers at cybersecurity firm Bitdefender concluded that Urban likely accessed music industry executives' accounts through SIM-swapping attacks — a technique in which attackers social-engineer mobile carriers into redirecting a victim's phone number to a device the attacker controls, thereby intercepting SMS-based authentication codes and gaining access to cloud accounts. The $13 million figure covered cryptocurrency theft from 59 victims; no formal charges in Urban's case specifically addressed the music leaks .
SIM-swapping as a technique is notable precisely because it bypasses strong passwords and most forms of two-factor authentication — it does not crack a system, it reroutes the phone number so that every SMS code lands in the attacker's hands instead. It is the same mechanism Urban and his Scattered Spider associates used to drain cryptocurrency wallets; the music theft and the financial fraud shared a technical foundation.
The FBI has separately documented the problem at industry scale. A March 2026 advisory from the FBI's Nashville Division — covering Internet Crime Complaint Center data from early January 2024 through late September 2025 — found that music industry professionals had filed 55 complaints reporting data breaches in which subjects obtained unreleased music from complainants' devices or gained access to their promotional social media accounts. The same FBI review found that 64 additional complaints involved extortion attempts leveraging stolen personal data or stolen unreleased material.
The lawsuit did not arrive without warning. In early 2024, appearing on the Zach Sang Show , Grande discussed "Fantasize," an unreleased track she had written for a television project that was stolen and later went viral on TikTok. "So 'Fantasize' comes out — 'comes out' — crazy — was stolen," she said . "Thieves, pirates, crooks, illegal. I'll see you in jail, literally."
Later in 2024, during a Hot Ones appearance, she described the cumulative experience as "disheartening" and "dehumanizing." "I am constantly trying to get to the bottom of like how people get stuff," she said . "Whether it's like videos or pictures or audio, songs." She acknowledged the tension between that frustration and gratitude for fans' engagement with her work, but made clear the theft was not something she intended to absorb indefinitely.
The complaint characterizes the ongoing leaks in language that goes beyond commercial harm: "The unauthorized misappropriation and disclosure of these materials is a violation of Ms. Grande's identity and artistry, and the direct and sacred relationship that exists between her and her fans." Her attorneys add: "Neither Ms. Grande nor any other public or private figure should have to suffer such violations caused by these wrongdoers who hide in the shadows and wreak technological havoc with impunity."
The complaint frames itself explicitly as a deterrent : "This lawsuit is intended to serve as a deterrent against future acts of this nature — not only targeting Ariana, but also the many artists who have faced similar invasions."
That framing signals something beyond a single artist defending herself. The civil discovery mechanism Grande is deploying — using subpoenas to unmask anonymous defendants rather than relying on a prior criminal identification — is more immediately accessible to artists than federal prosecution, which requires law enforcement agencies to prioritize and resource an investigation. If the strategy works and produces identifiable names, it establishes a template other artists in similar positions can follow.
The structural problem the case exposes, however, does not resolve through litigation alone. Every collaborator in a modern production chain — every photographer with a Dropbox folder, every producer whose mobile device stores unreleased masters, every digital technician receiving files via email — is a point of exposure that no individual artist controls. Addressing that exposure systematically would require the music industry to adopt security practices closer to those used in enterprise environments: credential audits for all third-party account holders, hardware-key 2FA requirements rather than SMS-based codes, end-to-end encrypted file transfer instead of cloud storage shared via login credentials, and contractual security obligations for anyone who handles pre-release material.
The lawsuit can identify and potentially penalize those who exploited those gaps. It cannot close them.
According to the complaint, the defendants targeted the accounts and devices of people in Grande's professional circle — photographers and producers who routinely handled her unreleased material. By compromising a photographer's Dropbox account, hacking a producer's mobile device, or impersonating trusted contacts via fake email addresses and domain names, attackers gained access to content they could never have reached by going after Grande directly. This approach — targeting less-secured third parties in a principal's production supply chain — is a recognized category of cyberattack that requires no breach of the target's own systems.
A John Doe civil complaint allows a plaintiff to file suit against unknown defendants using placeholder names, then use the court's discovery powers to compel identification. Once a judge grants discovery, Grande's legal team can serve subpoenas on internet service providers, cloud storage companies, email providers, and payment services like PayPal and Cash App — demanding account data, IP addresses, and transaction records associated with the alleged breaches and sales. If any of those records lead to identifiable individuals, the complaint can be amended to name them. Civil litigation gives artists a path to identification that doesn't depend on law enforcement prioritizing the case.
SIM swapping is a social engineering attack in which criminals convince or coerce a mobile carrier's customer service representative into transferring a victim's phone number to a SIM card the attacker controls. Once complete, the attacker receives all SMS messages and phone calls intended for the victim — including two-factor authentication codes — allowing them to take over email accounts, cloud storage, and other accounts even when the victim has a strong password. Researchers at Bitdefender attributed this technique to Noah Urban ("King Bob"), the Scattered Spider-linked leaker sentenced in August 2025, as the likely means by which he accessed music industry executives' accounts to steal unreleased material from Grande and others.
The attack vectors in this case — compromised cloud storage credentials, mobile device hacks, and BEC phishing — each have known mitigations. Hardware security keys (which cannot be intercepted the way SMS codes can) provide strong protection against SIM-swap-based account takeover. End-to-end encrypted file transfer tools offer better protection than cloud storage shared via login credentials. Domain verification tools (such as DMARC and DKIM email authentication) help recipients identify emails that impersonate legitimate senders. Contractual requirements mandating specific security practices for anyone handling pre-release material would extend these protections beyond the artist's own organization to their collaborators — the population this lawsuit shows is most at risk.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
