Spotify, based in Sweden, didn’t respond to a request for comment, but IBT reported that the company said it had not been breached and that, “our user records are secure.” A spokesperson added: He said someone could simply let the tool run all night and wake up to another 20,000 compromised accounts. He found a collection of emails and passwords on Pastebin – the anonymous service that lets people host text for free – and said that it took him about 15 minutes to break into 100 accounts using the tool. Hackers can easily collect login credentials – email addresses and passwords – that have been compromised from other breaches and are available on dark web marketplaces, sometimes for free, and then plug in those credentials to find a Spotify account associated with them. ![]() Without mechanisms to lock down an account after a certain number of incorrect password guesses, a brute force attack can simply keep guessing until it is successful. ![]() If not, you could be letting cybercriminals into your account.Ĭollective Labs’ Ryan Jackson came across a brute force hacking tool called Spotify Cracker v1 last month, which automatically cycles through known username and password combinations and breaks into Spotify accounts that use those credentials.ġ7-year-old Jackson, who reportedly has a history of involvement with hacking groups New World Hackers and Lizard Squad, (“while never participating in their antics”), told the International Business Times (IBT) that he found the tool on a private server on Discord – a popular, free online communications platform used primarily by gamers.Īnd given current Spotify login security protocols – the company doesn’t use CAPTCHAs or offer two-factor authentication (2FA) – it doesn’t meet much resistance. ![]() If you’re among the 140 million users who enjoy streaming music from Spotify – especially if you are one of its 60 million paying customers for “premium” services – you might want to make sure you have a strong, long and unique password on your account.
0 Comments
Leave a Reply. |