Spotify Gets Hit Again

Protection against credential stuffing isn’t something that a company like Spotify should struggle with, and suffering two credential stuffing incidents in one quarter shows a sloppy attitude toward security.

As many as 100,000 of the music streaming service’s customers could face account takeover.

Spotify has returned for another appearance with a credential stuffing disaster eerily similar. This time, data for approximately 100k users appeared in an Elasticsearch instance spotted by researchers. This is distinctly different data than the load that researchers discovered in November 2020.

No specifics were listed about the stolen data, but Spotify users should reset their account passwords and be on the lookout for spear phishing attempts.

“Spotify streaming music aficionados are in the crosshairs of yet another credential-stuffing cyberattack, just three months after the last one. The service has forced password resets for impacted users.

Cybercriminals carrying out credential-stuffing take advantage of people who reuse the same passwords across multiple online accounts. Attackers simply build automated scripts that systematically try stolen IDs and passwords (either gleaned from a breach of another company or website, or purchased online) against various types of accounts.”

Get In Touch

Share On Social Media

Other Recent Blog Articles

Safeguard Your Small Business: The Vital Role of IT Managed Services in Preventing Catastrophic Outages

April 12, 2024

In the fast-paced world of modern business, the reliance on technology has never been more significant. However, with this reliance comes the looming threat of cyberattacks, as evidenced by the…

Read More

Podcast Part 2: Special Episode – Aura Aesthetics

April 4, 2024

Welcome back to Breaking down I.T. with Steve and our special guest, Aura Aesthetics. Shifting our focus from skincare solutions, let’s delve into the realm of data security and HIPAA…

Read More

How AI is Revolutionizing Cybersecurity for Non-Technical Small Business Owners

April 3, 2024

In the fast-paced digital landscape, the undeniable rise of Artificial Intelligence (AI) has significantly reshaped the realm of cybersecurity, impacting small businesses in profound ways. For non-technical small business owners,…

Read More