What happened
vpnMentor researchers discovered an unsecured Elasticsearch database containing more than 380 million records, according to their report. The database stored Spotify login credentials, including usernames, passwords, email addresses, country of residence, and in some cases IP addresses. The researchers determined the database belonged to a third party that was using it to stage credential-stuffing attacks against Spotify. The incident did not originate from Spotify infrastructure.
Scope and data
The database held over 72 GB of data, as reported by the researchers. The IP addresses present were believed to originate from proxy servers operated by the actors hosting the database. The credentials were most likely obtained illegally from previous breaches on other platforms and repurposed for the Spotify campaign.
Response
Researchers notified Spotify on July 9, which immediately prompted a mandatory password reset for all affected users. Working with Spotify, the researchers confirmed that the database belonged to a group or individual using it to defraud Spotify and its users. The collaboration isolated the issue and protected customers from further attack.
Implications for credential hygiene
Credential-stuffing attacks exploit password reuse. Affected users face heightened risk of phishing emails designed to extract additional personal or financial information. Fraudsters can correlate exposed emails and names across other platforms and social media to build detailed profiles for financial fraud and identity theft. Resetting passwords on every account that shared the compromised credential combination remains the primary mitigation.