Fraudsters are sending fake Spotify emails that claim a recent payment could not be processed, in a phishing campaign designed to steal credit card details. The emails, which have been reported by multiple users, contain a sense of urgency, warning recipients that their access will be interrupted unless they update their payment information.
The message reads: “We encountered an issue while processing your recent payment. To keep your access active and avoid interruption, please review and update your information.” It then directs recipients to click a button labelled “update payment method,” adding: “This only takes a moment and helps ensure uninterrupted access to your account and services.” However, the email is not from Spotify. It is a scam.
Scam email imitates Spotify payment failure
The fake email is designed to look like a legitimate notification from Spotify, complete with the company’s branding and a professional tone. This level of polish is what makes it so dangerous, according to cybersecurity experts. The urgency—threatening that your access will be cut off—is a classic phishing tactic meant to short-circuit rational thinking and push recipients to act quickly without scrutinising the message.
Barry, a victim who contacted the Guardian, described how he was caught off guard. He said: “I saw the email on my phone while I was having a conversation and watching the tennis so just tapped the link to update the card without thinking about it.” He then faced immediate suspicious charges: “I was immediately hit with a suspicious credit card check for ‘Tm Connect’ followed by a Ticketmaster transaction in US$ for a sum equivalent to £469.22, which I declined.”
Distracted victim almost lost £469
Barry admitted that he never thought he would fall for such a trick. “I never thought I would be the kind of person to fall for a scam and I am exactly the kind of person to judge those who do. Luckily I use virtual credit cards for online subscriptions, so I could quickly cancel the card and change my unique Spotify password to limit the damage.” His experience highlights how even cautious individuals can be vulnerable when distracted, and how virtual cards can serve as a safety net against fraud.
The £469.22 amount is a significant loss, but Barry was fortunate to avoid it. His story echoes a growing trend of phishing scams targeting streaming service users. By mimicking trusted brands, fraudsters exploit the trust users place in familiar companies, making such attacks both effective and hard to spot.
Spotify's official warning
A Spotify spokesperson said: “Spotify takes the protection of users very seriously. We will never ask for personal information via email, including payment details, passwords, or government-issued identification numbers. We will also never request payments through third-party services or ask users to download files or software from our emails.” Spotify also warned that anyone who receives a suspicious message should not respond, click any links, or download attachments. Users who believe they may have already engaged with a suspicious email should immediately reset their Spotify password and review their account for unauthorised changes.
The company’s website offers additional guidance: “An email is suspicious if the sender email doesn’t end in ‘@spotify.com’, or if you’re simply not sure about it. Don’t respond to, click any links, or download anything in the email. If you already did: Reset your password. Change your password on any other sites where you use the same password. Contact your bank if you think your financial details have been compromised.”
How to avoid and respond to phishing scams
Spotify advises users to always check the sender’s email address carefully. Legitimate Spotify emails end in “@spotify.com”. Hovering over any links in an email can reveal whether they lead to a suspicious destination. Never enter your password or payment details on a page reached from an email link, as this could be a fraudulent mirror site.
- Check the sender address: any email not ending in @spotify.com is suspicious.
- Do not click links or download attachments from unsolicited messages, even if they look official.
- Use virtual credit cards for online subscriptions, as they can be cancelled quickly if compromised.
- If you have already clicked a link or entered details, reset your Spotify password immediately and contact your bank.
Phishing scams like this one are becoming increasingly common, but awareness is the best defence. By taking a moment to verify the authenticity of an email, you can avoid losing money and protect your personal information.



