this post was submitted on 23 Feb 2024
20 points (88.5% liked)

/c/cybersecurity - Cybersecurity News & Discussion

2090 readers
5 users here now

A community for technical news and discussion of cybersecurity and closely related topics.

founded 4 years ago
MODERATORS
 

So, yeah. Other than stated, Spotify does not provide 2FA (shame on them!), so I use a strong password and since years nothing happened.

This early morning I got multiple mails that my account was logged in from Brazil, from the USA, from India, and some other countries. There were songs liked and playlists created so it wasn’t a malicious e-mail but some people actually were able to log on to my Spotify account.

I of course changed the password and logged out all accounts and checked allowed apps, etc. and everything looks fine.

But I wonder … was there something that happened recently? The common sites to check such things do not list my old Spotify password, and a quick web research does not bring anything up.

Any clue what could have happened here?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 6 months ago

Regardless of what corporation it is. Always assume they got hacked.

Unless of course all their users' data is end to end encrypted, all with unique keys.

if a company like that gets hacked then it's like an intruder in an apartment complex, you got through the first door, now you need to break into each account one at a time.