Home/Incidents/Spotify

Spotify

9 Dec 2020 · National · Media & Entertainment
Credential Attack HIGH ✓ Verified

What happened

Spotify executed a massive rolling force-reset of user passwords after security analysts uncovered a cloud-hosted database containing active user credentials harvested via automated credential stuffing scripts. The data included user names, email indices, and regional profiles.

Incident details

Organisation
Spotify
Date
9 Dec 2020
Attack type
Credential Attack
Severity
HIGH
Sector
Media & Entertainment
State
National
Records affected
350000
Threat actor
Unknown

Source

au.finance.yahoo.com ↗
← Back to all incidents