With hundreds of millions of users worldwide, it’s no surprise that scammers use Spotify’s name and reputation to trick people.

Phishing scams involving Spotify have risen considerably, but there are a few ways you can avoid them.

fake spotify account alert email phishing scam

What Is a Spotify Phishing Scam?

Spotify phishing scams arrive in your inbox disguised as a regular message from Spotify. They typically claim something has happened to your account, your account password, or your account payment method and that immediate action is needed.

The two most common email subjects I’ve received are “Important ! We noticed unusual activity in your Spotify account” and “Your Premium payment failed,” both designed to trick you into clicking the link in the email. I’ve included images of these Spotify phishing emails below so you may check out what they look like.

spotify password reset email example

However, the email is fake, and the link takes you to a fake payment portal designed to steal your banking information. Note that when I scroll over the supposed link to reset my account or verify my details, the URL is a long, random alphanumeric string. It almost looks legit—but has nothing to do with Spotify at all.

Now, I don’t advise you to do this, but when I clicked through this link, my browser warned me that I was about to open a phishing link and that I should stop immediately.

How to Spot a Spotify Phishing Scam

While Spotify phishing emails are on the rise, they don’t bring anything new to the phishing email format. That is to say, while they can look convincing at a glance, they’reeasy to spot when you give them a little scrutiny, and it’s all about those little details.

Phishing emails are an annoying fact of life. There are afew ways you can avoid phishing emails, but if your email has ever been leaked as part of a data breach (or sold on by a website or service), they’ll appear in your inbox whether you like it or not.

Just remember the golden rule: if you don’t know where the email came from, don’t click the links.