Spotify Breach Hits Android Users

Music streaming service Spotfiy has disclosed a breach of its systems, but only a select group of customers appear to be affected, including Android device owners.

The company said it would start asking certain Spotify users to reset their username and password, and Android app users to upgrade over the next few days. It said iOS and Windows Phone versions were not affected.

Spotify hacked

Only one user was said to have had data compromised, but Spotify felt it necessary to take action anyway.

“We’ve become aware of some unauthorised access to our systems and internal company data,” said Oskar Stål, chief technology officer at Spotify, in a post on the firm’s website.

“Our evidence shows that only one Spotify user’s data has been accessed and this did not include any password, financial or payment information. We have contacted this one individual. Based on our findings, we are not aware of any increased risk to users as a result of this incident.”

Dwayne Melancon, CTO at Tripwire, said it seemed unlikely just one user’s credentials were affected.

“Had this been as simple as one user over-sharing their login credentials, it would not warrant an all-user notification. Given that Spotify claims that only one user’s data has been compromised, I suspect this was achieved via a re-usable, broadly applicable attack method perhaps affecting older versions of the Spotify app.

“My guess would be that someone demonstrated a proof-of-concept attack for the Spotify team and that constitutes the single known affected user.

“Users, particularly on the Android platform, should follow Spotify’s recommendation and ensure they are running up-to-date software.”

The attack has come just a week after eBay, the online auction giant, revealed it was hacked and asked all users to change their passwords.

Are you a security pro? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Northvolt Mulls US Bankruptcy Protection – Report

Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…

1 day ago

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

1 day ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

1 day ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

2 days ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

2 days ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

2 days ago