2020 Spotify — registration API bug exposed account fields to certain business partners (Apr–Nov)
Data compromised
Account enrollment fields enumerated in CA AG-filed consumer notice templates
Technical writeup
Spotify disclosed a software defect that, between April 9 and November 12, 2020, could share registration-bundle attributes—email, display name, password hash, gender, DOB—with selected business partners through normal integration flows rather than public internet scraping. The company reset passwords for the impacted small subset of accounts, coordinated partner deletion, and filed California breach paperwork. TechCrunch framed it alongside contemporaneous credential-stuffing noise to separate first-party logic bugs from stolen password reuse.
Root cause
Application/integration flaw that over-exposed user profile objects to partner channels