Spotify Credential Stuffing: The 2020 Incident

What happened

vpnMentor researchers discovered an unsecured Elasticsearch database containing more than 380 million records, according to their report. The database stored Spotify login credentials, including usernames, passwords, email addresses, country of residence, and in some cases IP addresses. The researchers determined the database belonged to a third party that was using it to stage credential-stuffing attacks against Spotify. The incident did not originate from Spotify infrastructure.

Scope and data

The database held over 72 GB of data, as reported by the researchers. The IP addresses present were believed to originate from proxy servers operated by the actors hosting the database. The credentials were most likely obtained illegally from previous breaches on other platforms and repurposed for the Spotify campaign.

Response

Researchers notified Spotify on July 9, which immediately prompted a mandatory password reset for all affected users. Working with Spotify, the researchers confirmed that the database belonged to a group or individual using it to defraud Spotify and its users. The collaboration isolated the issue and protected customers from further attack.

Implications for credential hygiene

Credential-stuffing attacks exploit password reuse. Affected users face heightened risk of phishing emails designed to extract additional personal or financial information. Fraudsters can correlate exposed emails and names across other platforms and social media to build detailed profiles for financial fraud and identity theft. Resetting passwords on every account that shared the compromised credential combination remains the primary mitigation.

Back to the blog index