← Spotify Technology

2020 Spotify — registration API bug exposed account fields to certain business partners (Apr–Nov)

2020 Unknown records affected Share on X

Data compromised

Account enrollment fields enumerated in CA AG-filed consumer notice templates

Technical writeup

Spotify disclosed a software defect that, between April 9 and November 12, 2020, could share registration-bundle attributes—email, display name, password hash, gender, DOB—with selected business partners through normal integration flows rather than public internet scraping. The company reset passwords for the impacted small subset of accounts, coordinated partner deletion, and filed California breach paperwork. TechCrunch framed it alongside contemporaneous credential-stuffing noise to separate first-party logic bugs from stolen password reuse.

Root cause

Application/integration flaw that over-exposed user profile objects to partner channels

References