Spotify Security Breach Could Put Your Private Information at Risk

 By 
Jennifer Van Grove
 on 
Spotify Security Breach Could Put Your Private Information at Risk
Mashable Image
Credit:

So what's the damage? According to Spotify, "Along with passwords, registration information such as your email address, birth date, gender, postal code and billing receipt details were potentially exposed. Credit card numbers are not stored by us and were not at risk."

As noted below in the comments, it was the password hashes that may have been exposed, not plain text passwords.

The blog post urges members who created accounts on or before December 19th, 2008 — the date a known bug was fixed — to change their password for Spotify and any other sites where they were using the same password.

So what happened? A group of hackers compromised Spotify protocols due to a bug in a system that the company reportedly fixed on December 19th. The post states that, "the information that may have been exposed when our protocols were compromised is the password hashes. As stated, we never store passwords, and they have never been sent over the Internet unencrypted, but the combination of the bug and the group’s reverse-engineering of our encrypted streaming protocol may have given outsiders access to individual hashes."

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!