HomeSecuritySpotify: should I change my password after the latest data breach?

Spotify: should I change my password after the latest data breach?

Spotify has reset passwords for some usersafter discovering a security flaw that could have exposed account information.

Spotify

The music streaming platform has notified the California Attorney General's Office of a breach, describing the incident, what information was involved, and what actions it has taken to address the issue. The statement comes after recent news that at least 300,000 Spotify accounts are believed to have been compromised, with email addresses, login credentials, and other data leaked.

California law requires organizations to notify residents whose unencrypted personal information may have been compromised by unauthorized parties. If the incident affects more than 500 California residents, a copy of the notification must be submitted electronically to the state attorney general. This was the case with Spotify, which sent a letter via email.

The alert was sent on December 9, 2020, but Spotify says the vulnerability dates back to April 9, 2020, and was discovered on November 12, 2020. It says that users’ registration information was affected, including their email address, name, password, gender, and date of birth. This data may have been exposed to certain business partners. In addition to resetting affected users’ passwords and sending notifications, Spotify says that an internal investigation has been conducted and that any business partners who may have had access to the data have been notified and asked to delete it.

Spotify: should I change my password after the latest data breach?

Spotify has contacted users affected by the breach and asked them to reset their passwords as a precautionary measure. Users who have not received any notification and are still accessing the platform are not affected and do not need to do so. Spotify also notes that it has “no reason to believe that any unlawful use of the information has occurred or will occur.”

However, data breach notification is an issue that should not go unnoticed by users. Cybersecurity experts adviseusers to change their passwords every one to three months. This may sound like a bit of an exaggeration, but research has shown that the older a password is, the more likely it is to have been compromised.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS