Announcements

Help Wizard

Step 1

NEXT STEP

FAQs

Please see below the most popular frequently asked questions.

Loading article...

Loading faqs...

VIEW ALL

Ongoing Issues

Please see below the current ongoing issues which are under investigation.

Loading issue...

Loading ongoing issues...

VIEW ALL

Spotify hacked - serious platform hole

Reply

Spotify hacked - serious platform hole

This is my third attempt to post this.

 

Spotify has a serious security hole allowing hackers to take controls of account without authorization. This morning I found my Spotify playing random songs across random devices with names which seem to indicate the account was being hacked (see images attached).

I did what Spotify asked:

1. Changed my password

2. Log out of all devices

3. Revoke access to all apps

 

After logging in again I found the same issue, a mysterious Web browser (Chome) would pop up in my list of devices and it would play a random song. It was real time hacking! I would change the song and device and a few seconds later it would switch to a different song with a new name and again the Web browser chrome device would show up (I tried deleting it multiple times but it would show up again). All this after changing password. Someone has backend access to Spotify accounts in real time.

 

I've attached a snapshot showing this random Browser device which keeps showing up.

 

File_006.png
File_004.png
File_002.png
7 Replies

Here are three more songs that randomly played when I tried to select a different song AFTER changing my password for a SECOND time and deleting all devices. Once again the mysterious Web player Chrome shows up out of nowhere. Clearly someone has access to Spotify without being properly authenticated.

 

Spotify claims that that their platform is secure, evidence shows that it is far from it! Spotify wake up and secure your platform!

 

 

File_001.png
File_003.png
File_005.png

Did you ever resolve, exactly same is happening to me? Thanks 

Nope, no one contacted me or responded to the post. Those songs were in a language I didnt recognize and never heard. My guess is that Spotify is just ignoring it and hoping no one notices if you’re still seeing the issue. 

I've never seen or heard of this issue before. But now that I'm aware I should use my extensions to secure Spotify a little more. I have had experience with hacking on other platforms, but never on the platform. I mainly use Spotify for my school so the school has a system that doesn't allow random people into the software. 🖥

 

It's very interesting how someone (you don't know) has access, otherwise I can try to find the system my school uses and you could use it for yourself. If you'd like. 

 

But I do have a question..And it could be why. Have you ever given any of your friends or family access? Like, putting it on a TV or their Web Browser to show them how to sign in or something? Because they might still have access to it. 

 

DISCLAIMER: I'm not a professional, it's just what I've done to solve the issue of people having my account. 

Never given anyone access. It’s a secure randomly generated password. Plus I’ve never received any notification that new device was used to login (which is what I get for new device). This a backend platform hack / hole that Spotify has or had. 

Also notice how some of the songs are created by the same person. If you possibly know someone that likes music from this creator, then it could be them. Otherwise, I'm wrong, but I'll try to help as much as I can. Message me if you can.

Interesting. Well, I'm not telling you to install this, but if you are desperate (which seems obvious) then you could install LastPass. Which my grandfather uses. I recommend it (NOT ADVERTISING). And hopefully you get this issue solved. 👍

Suggested posts