Music streaming service Spotfiy has disclosed a breach of its systems, but only a select group of customers appear to be affected, including Android device owners.
The company said it would start asking certain Spotify users to reset their username and password, and Android app users to upgrade over the next few days. It said iOS and Windows Phone versions were not affected.
Only one user was said to have had data compromised, but Spotify felt it necessary to take action anyway.
“Our evidence shows that only one Spotify user’s data has been accessed and this did not include any password, financial or payment information. We have contacted this one individual. Based on our findings, we are not aware of any increased risk to users as a result of this incident.”
Dwayne Melancon, CTO at Tripwire, said it seemed unlikely just one user’s credentials were affected.
“Had this been as simple as one user over-sharing their login credentials, it would not warrant an all-user notification. Given that Spotify claims that only one user’s data has been compromised, I suspect this was achieved via a re-usable, broadly applicable attack method perhaps affecting older versions of the Spotify app.
“My guess would be that someone demonstrated a proof-of-concept attack for the Spotify team and that constitutes the single known affected user.
“Users, particularly on the Android platform, should follow Spotify’s recommendation and ensure they are running up-to-date software.”
The attack has come just a week after eBay, the online auction giant, revealed it was hacked and asked all users to change their passwords.
Are you a security pro? Try our quiz!
Welcome to Silicon UK: AI for Your Business Podcast. Today, we explore how AI can…
Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…
Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…
Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…
Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…
Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…