Type in your question below and we'll check to see what answers we can find...
Loading article...
Submitting...
If you couldn't find any answers in the previous step then we need to post your question in the community and wait for someone to respond. You'll be notified when that happens.
Simply add some detail to your question and refine the title if needed, choose the relevant category, then post.
Before we can post your question we need you to quickly make an account (or sign in if you already have one).
Don't worry - it's quick and painless! Just click below, and once you're logged in we'll bring you right back here and post your question. We'll remember what you've already typed in so you won't have to do it again.
Please see below the most popular frequently asked questions.
Loading article...
Loading faqs...
Please see below the current ongoing issues which are under investigation.
Loading issue...
Loading ongoing issues...
Hi Spotify User
To protect your Spotify account, we've reset your password. This is because we believe it may have been compromised during a leak on another service with which you use the same password.
So...
How do they know what my passoword is?
How would they know it was the same on another service?
Has anybody else received this? I see a major security flaw here if passwords are not encrypted.
Jim
Hey @jtpryan,
I haven't received one myself, but I've seen multiple reports from several users getting them. Was your password actually resetted? I wonder if it's not a phishing message.
Thanks for the reply. That was my first thought. But the reason I searched my email was because I had in fact been locked out. I looked closely as to where it was sending me before resetting the PW and once done, I could get back in.
My conculsion is that this is either extremly sophistaticated on the part of phishing or that Spotify presents a real problem. I'm a System Adminstrator by trade so I am familiar with cyber security. Of course, there is no way to contact them unless you can log in. But, if one of my users forgot their PW the only recorse I have is to reset it, I can never, ever, see it. Not in Linux, Windows, etc. Much less be able to tell it was the same somewhere else.
I guess now I wait to hear from them or the other shoe fall.
Jim
So why don't they state that? Why the need to lie? Such a great service; but a message like this is unconscionable given security concerns these days. Leaves one with very little trust.
Hey @jtpryan!
Thanks for reaching out to the Spotify Community.
We appreciate your concern. To be clear, Spotify has not been compromised and your data is secure. We proactively reset your password as a precaution because we found that another website or service, where you also use that password, was compromised.
We monitor Pastebin and other sites regularly. When we find Spotify credentials, we first verify that they are authentic, and if they are, we immediately notify affected users to change their passwords. We're afraid we can’t provide any further information about the status of your details on other services.
Let us know if you have any other questions; we'll be right here for you.
Thanks and have a great day.
This clears nothing up and certainly adds to the concern.
"We proactively reset your password as a precaution because we found that another website or service, where you also use that password, was compromised."
Can this be explained in some way that does not lead me to believe you have access to my password (in clear txt) on both your own systems and others?
"We monitor Pastebin and other sites regularly. When we find Spotify credentials, we first verify that they are authentic, and if they are, we immediately notify affected users to change their passwords."
Again, exactly how do determine this unless you know what my password is? I have never been to Pastebin and what exactly are "other sites"?
"We're afraid we can’t provide any further information about the status of your details on other services."
Well, given the red flags you have thrown up around this you darn well better provice some information.
I specifically want an answer as to how you compared my password to anything without being able to read it.
Thank you,
Jim
We understand where you're coming from, but if you'd like us to provide you with more info on this, we strongly recommend you to contact us via email, Facebook or Twitter. Make sure to send the link to this post along with the message.
Rest assured we'll do our best to clear things up for you.
Thanks again for your concern and have a great day.
Hey there you, Yeah, you! 😁 Welcome - we're glad you joined the Spotify Community! While you here, let's have a fun game and get…