Announcements

Help Wizard

Step 1

NEXT STEP

FAQs

Please see below the most popular frequently asked questions.

Loading article...

Loading faqs...

VIEW ALL

Ongoing Issues

Please see below the current ongoing issues which are under investigation.

Loading issue...

Loading ongoing issues...

VIEW ALL

Password Reset Due to Suspicious Activity - False Report

Password Reset Due to Suspicious Activity - False Report

Plan

Premium

Country

US

 

My Question or Issue

Every few months or so I get signed out of all devices, then receive an email stating:

 

To protect your Spotify account, we've reset your password due to detected suspicious activity.

You need to create a new password to log back in. Just click the big green button.

 

I went into Login Methods last time, and completely removed the Email and Password option, so only Google shows up, meaning OAuth.  However just today all of my devices were logged out, and I received the password reset email.  However I DON'T even have a password, that's extremely frustrating.  It's like if people got your email or user from another list, they can basically try to log into your account and lock it out at ANY TIME.

 

Spotify login system should be smart enough to know that Email and Password is no longer accepted and stop forcing a password reset when it's NOT a valid login option.  This is an inherit flaw in your security system.

Reply
7 Replies

Hi there @user12650,

 

Thanks for reaching out. Removing the email address of an account isn't really possible, as it needs to be present to identify the account and to allow its recovery. Consider following all the steps suggested here to secure your account. If you continue to face issues after that, consider reaching out to our support team so they can help you secure the account further.

 

Hope this helps.

JoanModerator
Help others find this answer and click "Accept as Solution".
If you appreciate an answer, maybe give it a Like.
Are you new to the Community? Take a moment to introduce yourself!

Hi,

 

I'm not asking for the email to be removed, like I mentioned, it's removed as a Login Method.

 

Go to your Account, under Security and Privacy section, click Edit Login Methods

 

Currently, my ONLY login method is Google, i.e. they NEED to log into my GOOGLE account to get into Spotify, which is completely protected by 2FA. See below, I DO NOT have Email and Password selected, so it's not usable.

 

spotify-login-methods.png

 

Yet somehow, again today, Spotify reset my password, a password I DO NOT use, based on the login methods selected above.  The result of this, Spotify signs me out of every app.

Hey @user12650,

 

Thanks for getting back to us. 

 

In this case, we'd recommend reaching out to our Support team as @Joan mentioned above. They'll be able to check your account and provide further details if possible. 

 

If anything else comes up, the Community will be here.

NovyModerator
Help others find this answer and click "Accept as Solution".
If you appreciate an answer, maybe give it a "Like".
Are you new to the Community? Take a moment to introduce yourself!

I don't use a VPN.

 

I use long secure passwords that are randomly generated. I do not re-use passwords among different accounts.

 

If you can't tell me what "suspicious activity" you are protecting my account against, then you are just wasting my time.

 

As many posters have already suggested, you need to implement a "was this you?" response to "suspicious activity" instead of forcing users to reset their password over and over and over again.

Had to reset my password again today.

 

I don't use a VPN.

 

I use strong passwords.

 

I don't re-use passwords across different accounts.

 

If you can't tell me what suspicious activity is causing these emails then you are just wasting my time.

Got another "we've reset your password due to detected suspicious activity" email today! Wonder how many I can rack up.

 

So much fun to change my password every week and then have to re-enter that password on all my devices. Yay spotify!

It's very weird how Spotify detects "suspicious activity" on my account on a weekly basis, almost like clockwork, but is unable to give me any information about what this "suspicious activity" might be. Extremely unhelpful and annoying to have to change my password every week for seemingly no reason.

 

I don't use a VPN.

 

I use unique, strong, randomly-generated passwords.

 

Your "suspicious activity" algorithm is broken.

Suggested posts