Ariana Grande’s Hackers Never Broke Into Her Accounts, They Broke Into Everyone Around Her

A woman with a long ponytail stands with folded arms beside a large mixing console in a dim studio control room, facing the darkened vocal booth glass

Ariana Grande sued 100 anonymous defendants in Los Angeles County Superior Court on Monday over a hacking campaign that has been draining her unreleased music into the internet for years.

According to the complaint, not one of the intrusions targeted her.

They went after her photographer’s Dropbox. Her producers. The technicians who move files around a studio at 2 a.m. Everybody who touches an unreleased master and does not have a security budget.

The Attack Nobody in Music Is Set Up to Stop

The suit names John Doe 1 and John Does 2 through 100, and it tells a story that will be familiar to anyone who works in corporate security and unfamiliar to almost everyone in the record business. Rolling Stone reported the filing on Monday, and the pattern inside it is consistent: phishing emails and credential theft aimed at collaborators, then quiet extraction of whatever those accounts happened to hold.

The dates in the complaint are specific. In 2019, the defendants allegedly got a photographer’s Dropbox credentials and pulled down unreleased photographs. In 2023, 45 unreleased songs were taken and leaked, a figure that is difficult to sit with if you have ever written one. Two more phishing attacks in 2024 produced unreleased images. Along the way, the filing says, the haul included masters and demos still in production, music-video footage, studio session recordings, behind-the-scenes shots and shoot outtakes.

A pop star can lock down her own accounts. Hardware keys, dedicated devices, a security consultant on retainer, the whole apparatus. What she cannot do is make the same investment on behalf of a freelance photographer in another city whose entire business runs out of one cloud account and one email address protected by a password from 2017.

That asymmetry is the story. The perimeter around a modern artist is not the artist. It is a loose federation of contractors, and attackers figured that out long before the industry did.

A John Doe Suit Is a Discovery Engine

Suing people whose names you do not know sounds futile. It is actually the point.

Filing against John Does unlocks the civil discovery process, and discovery is how you turn a pseudonym into a person. Once a court signs off, Grande’s lawyers can subpoena the platforms that hold the fingerprints: cloud services for account and access logs, email providers for IP addresses, and payment processors for the trail left behind when leaked files get sold. Match an IP to a subscriber, match a payout to a bank account, then amend the complaint with real names and serve them.

She also picked her claims for reach rather than drama. Invasion of privacy, conversion, and violations of California’s computer access and fraud statute travel well together, and Stereogum noted the aim is to unmask the people behind the leaks rather than to collect from ghosts. Copyright would have been the obvious hammer, and it would have pushed the case into federal court under a statutory framework built for infringement, not for the actual injury here, which is years of somebody rifling through her workplace.

Whether it works depends on operational security that has nothing to do with music. Attackers who used commercial VPNs, prepaid crypto and burner accounts may be genuinely unreachable. Attackers who got sloppy once, and people running a campaign this long usually do, are findable. The leak scene is also social, which means somebody in it has been bragging in a Discord server that keeps logs.

The Fan Economy That Pays for This

Here is the part the coverage tends to leave out, because it implicates the audience.

Leaked unreleased music is not a byproduct. It is a market with pricing, brokers, reputations and resale, and it exists because a meaningful slice of fandom treats a stolen demo as a collectible instead of stolen property. Grande has spent years watching songs she chose not to release circulate as trophies, sometimes with her own vocals in versions she rejected.

The harm is not abstract, and it is not really about money. An unreleased song is a work in progress, which means the leaked version is a draft the artist judged not good enough. Publishing it strips out the one thing an artist controls, which is when the work is finished. Nobody would circulate a novelist’s rejected third chapter and call it a gift to readers.

The Grande version of this problem also runs alongside a physical one. Stars now manage security threats on multiple fronts at once, from the digital perimeter in this lawsuit to the kind of case that ended with Sabrina Carpenter obtaining a restraining order against a stalker who kept turning up at her house. The industry staffs heavily for the second category and barely at all for the first.

What Should Change, and Probably Will Not

Fixing this does not require new law. It requires labels and management companies to treat every collaborator as part of the attack surface, which means funding hardware security keys and mandatory two-factor authentication for anyone who receives an unreleased file, providing a managed transfer system instead of consumer cloud links, and writing security requirements into contractor agreements the way confidentiality clauses already are.

None of that is expensive relative to a single album campaign. All of it is annoying, and annoying is what kills security programs.

So the more likely outcome is the one already in motion: an artist with resources spends her own money to chase anonymous defendants through a subpoena process, wins or does not, and every other artist keeps emailing files to a photographer whose password is her dog’s name. Grande is fighting for a discovery order. What the business actually needs is a locksmith.