Spotify Breach Hits Android Users

Music streaming service Spotfiy has disclosed a breach of its systems, but only a select group of customers appear to be affected, including Android device owners.

The company said it would start asking certain Spotify users to reset their username and password, and Android app users to upgrade over the next few days. It said iOS and Windows Phone versions were not affected.

Spotify hacked

Only one user was said to have had data compromised, but Spotify felt it necessary to take action anyway.

“We’ve become aware of some unauthorised access to our systems and internal company data,” said Oskar Stål, chief technology officer at Spotify, in a post on the firm’s website.

“Our evidence shows that only one Spotify user’s data has been accessed and this did not include any password, financial or payment information. We have contacted this one individual. Based on our findings, we are not aware of any increased risk to users as a result of this incident.”

Dwayne Melancon, CTO at Tripwire, said it seemed unlikely just one user’s credentials were affected.

“Had this been as simple as one user over-sharing their login credentials, it would not warrant an all-user notification. Given that Spotify claims that only one user’s data has been compromised, I suspect this was achieved via a re-usable, broadly applicable attack method perhaps affecting older versions of the Spotify app.

“My guess would be that someone demonstrated a proof-of-concept attack for the Spotify team and that constitutes the single known affected user.

“Users, particularly on the Android platform, should follow Spotify’s recommendation and ensure they are running up-to-date software.”

The attack has come just a week after eBay, the online auction giant, revealed it was hacked and asked all users to change their passwords.

Are you a security pro? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

SoftBank Promises To Invest $100bn In US

Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…

20 hours ago

Synopsys, SiMa.ai To Collaborate On AI Car Chips

Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…

20 hours ago

AI Start-Up Basis Raises $34m For Accountancy Agent

Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…

21 hours ago

Databricks Raises $10bn In Huge AI Funding Round

Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…

21 hours ago

Congo Files Complaints Against Apple Over Conflict Minerals

Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…

22 hours ago