Fine-tune Your Passwords! Researchers Find Hackers Targeting Spotify Users

Date:

Share post:

Security experts from vpnMentor uncovered a potential credential stuffing attack exploiting the personal data of Spotify users. The researchers found an unencrypted Elasticsearch database containing over 380 million records holding login credentials and other personal details of the music streaming service users. In credential stuffing attacks, cybercriminals take advantage of weak and reused passwords of consumers with the hope of eventually guessing correctly.

The threat actors behind the exposed database are unknown, however, they abused stolen login credentials to compromise Spotify accounts. “Working with Spotify, we confirmed that the database belonged to a group or individual using it to defraud Spotify and its users. We also helped the company isolate the issue and ensure its customers were safe from attack,” vpnMentor said.

Threat Summary:

Origin of the Database

vpnMentor’s researchers stated that the exposed database belonged to a third-party service provider that was using it to save Spotify users’ login details. It is found that attackers illicitly obtained user credentials from data breaches and from other sources.

“This is a common tactic used by cybercriminals to access private accounts on popular platforms like Spotify, and something the company — like most online businesses — has dealt with in the past, given the pervasive use of weak passwords by so many consumers online. Companies cannot prevent this from occurring since they do not control the passwords that consumers use (and re-use) online. But they can play a role by helping users regain control of their accounts and promoting safer password practices by users, which Spotify did in this case,” vpnMentor added.

Spotify notified the affected users to reset their passwords as a security measure.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...