Connect with us

Technology

Spotify playlists are being hijacked to promote pirated software and scams

Published

on

Spotify playlists are being hijacked to promote pirated software and scams

Many of us use Spotify every day, whether to listen to songs, podcasts or audiobooks. Some of us create playlists of our favorite songs, while others save playlists made by others. 

In case you didn’t know, Spotify allows you to create public playlists that anyone can save and listen to. You’d think this is a harmless feature, but spammers have found a way to misuse it. 

They’re using Spotify playlists and podcasts to push pirated software, game cheat codes, spam links and malware sites. I’ll discuss the details of this emerging online scam and share tips on how to stay safe.

5 DAYS LEFT! I’M GIVING AWAY A $500 GIFT CARD FOR THE HOLIDAYS (ends 12/2/24 12 pm PT)

Image of Spotify app on phone (Kurt “CyberGuy” Knutsson)

Advertisement

How the Spotify scam works

As reported by BleepingComputer, this scam works by misusing Spotify’s popularity and trustworthiness. Scammers exploit Spotify playlists by injecting targeted keywords, such as “free download,” “crack” or “warez,” into titles and descriptions. 

These keywords are designed to align with popular search terms. Since Spotify’s web player pages are indexed by search engines like Google, these spammy results appear in user searches, driving traffic to their links. For example, a Spotify playlist titled “Sony Vegas Pro 13 Crack…” was found promoting “free” software sites in its title and description, directing users to questionable external links.

The scam isn’t limited to playlists. It extends to podcasts as well. Scammers create podcasts with multiple short episodes, typically under 20 seconds, using synthesized speech to direct listeners to click links in the description for free content. These podcasts often target users searching for pirated ebooks, audiobooks or game cheats. While the content may appear legitimate at first glance, clicking on the links often results in being redirected to unsafe pages that further exploit users.

spotify hijack 2

Scammers exploit Spotify playlists by injecting targeted keywords into titles (BleepingComputer)

4.3 MILLION AMERICANS EXPOSED IN MASSIVE HEALTH SAVINGS ACCOUNT DATA BREACH

The end goal

The main goal of this scam is to use Spotify’s trusted reputation and search engine visibility to get people to click on shady links and visit sketchy websites. Scammers make money through fake ad clicks, bogus surveys and affiliate links, while also spreading malware by tricking users into downloading harmful software or extensions. 

Advertisement

They also try to steal personal info through fake sign-up forms or phishing pages, which can lead to identity theft or be sold to others. By using Spotify’s indexed pages, they boost the search rankings of their spam sites, reaching more people. Some of these sites even run extra scams like fake crypto giveaways or phishing attempts to grab even more money or data from unsuspecting users.

spotify hijack 3

Spotify playlist promoting Sony Vegas Pro “crack” (BleepingComputer)

MASSIVE SECURITY FLAW PUTS MOST POPULAR BROWSERS AT RISK ON MAC

7 ways to stay safe from Spotify scams

1. Avoid clicking on suspicious links: Be cautious when you come across playlists or podcasts with titles like “Sony Vegas Pro 13 Crack” or other promises of free software, audiobooks or game cheats. These often include links in the description that redirect to unsafe sites hosting malware, adware or phishing pages.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.

Advertisement

2. Stick to official sources: Always download software, eBooks or other digital content from trusted official websites or reputable platforms. If you see a Spotify playlist or podcast offering “free” versions of paid content, it’s likely a scam. Cross-check the legitimacy of the content through known channels instead of relying on unverified links.

3. Use strong, unique passwords: Create complex and unique passwords for your Spotify account and avoid using personal information like birthdays or pet names. Consider using a password manager to generate and store complex passwords.

4. Be skeptical of synthesized speech and short episodes: Many scam podcasts feature short episodes (10-20 seconds) with synthesized speech directing you to click on a link in the description. These are a common tactic used to trick users into visiting unsafe pages. If the content feels automated, vague or overly promotional, it’s best to avoid it.

5. Verify curator credentials: Check the credentials of playlist curators. Legitimate curators usually have a verifiable online presence. If you can’t find any information about them, it’s best to avoid engaging with them.

Advertisement

6. Recognize phishing attempts: Be cautious of emails claiming to be from Spotify that ask you to confirm account details or click on suspicious links. These are often phishing attempts designed to steal your credentials.

7. Report and block suspicious content: If you come across playlists or podcasts that seem fraudulent or inappropriate, report them directly to Spotify. Use Spotify’s reporting tools to flag content that violates its platform rules. Blocking suspicious accounts or playlists also ensures you won’t accidentally interact with them in the future, and reporting helps Spotify improve its filtering and moderation systems.

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET

Kurt’s key takeaway

Scammers will use any means possible to trick you. In the past, we’ve seen bad actors weaponize Google search results with malicious websites that install malware when links are clicked on. There have also been plenty of SEO scams targeting users. Companies like Spotify need to implement measures to prevent their platforms from being misused by scammers. Google also has a responsibility to ensure the quality of its search results. Just because a webpage comes from a well-known organization doesn’t mean it deserves to rank highly on the search results pages.

Advertisement

Do you think platforms like Spotify and Google are doing enough to prevent scams, or could they improve? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most asked CyberGuy questions:

Advertisement

New from Kurt:

Try CyberGuy’s new games (crosswords, word searches, trivia and more!)

Enter CyberGuy’s $500 Holiday Gift Card Sweepstakes

KURT’S HOLIDAY GIFT GUIDES 

Deals: Unbeatable Best Black Friday deals | Laptops | Desktops | Printers 

Advertisement

Best gifts for Men | Women | Kids | Teens | Pet lovers 

Copyright 2024 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Tesla’s robotaxi is live: here are some of the first reactions

Published

on

Tesla’s robotaxi is live: here are some of the first reactions

Tesla finally did the damn thing. The company launched its hotly anticipated robotaxi service in Austin, Texas, on Sunday, June 22nd — and we’re now starting to see some of the first reactions roll in.

But first, we have to get a few important caveats out of the way. Tellingly, the service is not open to the general public, nor is it completely “unsupervised,” as Elon Musk once promised. The vehicles will include Tesla-employed “safety monitors” in the front passenger seat who can react to a dangerous situation by hitting a kill switch. Other autonomous vehicle operators would place safety monitors in the driver or passenger seats, but typically only during the testing phase. Tesla is unique in its use of safety monitors during commercial service.

The rides are limited to a geofenced area of the city that has been thoroughly mapped by the company. And in some cases, Tesla is using chase cars and remote drivers as additional backup. (Some vehicles have been spotted without chase vehicles.)

The service is invite only at launch, according to Tesla’s website. A number of pro-Tesla influencers have received invites, which should raise questions about how unbiased these first critical reactions will be. Tesla hasn’t said when the service will be available to the general public.

The limited trial includes 10-20 Model Y vehicles with “Robotaxi” branding on the side. The fully autonomous Cybercab that was first revealed last year won’t be available until 2026 at the earliest. The service operates in a small, relatively safe area of Austin from 6AM to 12AM, avoiding bad weather, highways, airports, and complex intersections.

Advertisement

Despite those hours, the robotaxi service seems to have gotten off to a slow start. Several invitees had yet to receive the robotaxi app by 1PM ET on Sunday. Sawyer Merritt, who posts pro-Tesla content on X, said he saw 30 Waymo vehicles go by while waiting for Tesla’s robotaxi service to start. Musk posted at 1:12PM that the service would be available later that afternoon, adding that initial customers would pay a “flat fee” of $4.20 for rides — a weed joke with which Musk has a troubled history.

While riders waited, the company published a new robotaxi page to its website detailing a lot of the rules and guidelines of the service. Visitors are invited to sign up for updates about when Tesla’s robotaxi service may come to their area. (Musk has said there could be up to a thousand robotaxis on the road “in a few months.”)

After finally being granted access to the app, Merritt posted an image of the service area map, which appeared to cover a small area bordered by the Colorado River to the north, Highway 183 to the east, Highways 290 and 71 to the south, and Zilker Part to the west.

And then the rides began — and they appeared to be mostly uneventful. Several invitees livestreamed themselves summoning their first cars, interacting with the UI, and then arriving at their destination. Several videos lasted hours, as the invitees would conclude a trip and then hail another car immediately after. One tester, Bearded Tesla Guy, described the app’s interface as “basically Uber.” Many had some difficulty finding the pickup location of their waiting Tesla robotaxi.

“This is like Pokemon hunting,” one person on Herbert Ong’s livestream said, “but its robotaxi hunting.”

Advertisement

Once inside, the Tesla-employed safety monitor would ask the riders to show their robotaxi apps to prove their identities. Otherwise the safety monitors kept silent throughout the ride, despite riders trying to get them to talk. I’m assuming that Tesla will need to come up with some other way to identify their riders if they plan on removing the safety monitors from the passenger seat. Waymo, for example, asks customers to unlock their vehicle through the ridehail app.

The rear screen instructs the riders to fasten their seatbelts, and after pressing an animated “start ride” button, the vehicle gets underway. Riders can also start the ride from a similar button in the app. Since riders are registering for the robotaxi app using their preexisting Tesla profiles, they’re greeted with their preferred music apps on the rear screen with all their playlists and saved tracks.

The front display shows a visualization similar to consumer vehicles using Tesla’s Full Self-Driving feature — even though Musk had said the robotaxis are running on a special version of FSD that’s not available to the average Tesla owner. There are “pull over,” “stop in lane,” or “support” buttons on the center display. Another tester, Chuck Cook, said the visualization lacked some of the controls that a normal Tesla might have.

Pressing the support button places the rider in a queue as they wait for the remote operator to connect. On Cook’s livestream, it took approximately two minutes before an operator finally connected. “We appreciate you calling in,” the operator said (though the cellular connection was poor). “We’re here for any issues to support your ride.”

Throughout the various trips, the robotaxis encountered a bevy of normal situations, like U-turns, speed bumps, pedestrians, construction, and more. The vehicles maintained speeds of about 40 mph or slower. Common words to describe the ride was “smooth,” “great,” and “normal.” One tester said on X that they got the robotaxi to “mess up” in a way that required the remote operator to help out — though they declined to describe it as a disengagement.

Advertisement

Ashok Elluswamy, the head of the company’s self-driving team, posted a photo of several dozen people in a room with 10 large monitors on the wall showing live camera feeds from several vehicles. “Robotaxi launch party,” Elluswamy wrote.

Where Tesla goes from here is the real challenge. Musk has said he also wants to launch a robotaxi service in California, where the regulatory process is a lot more complex than Texas. And even though he has said he wants to take things slow, he also claims that Tesla will have over a thousand driverless vehicles on the road “within a few months.”

Meanwhile, Waymo is operating more than 1,500 driverless vehicles in San Francisco, Los Angeles, Phoenix, and Austin — with plans to expand to Atlanta, Miami, and Washington, DC in the near future. The Alphabet-owned company has said it will grow its fleet to 2,000 vehicles by next year.

Continue Reading

Technology

Suicide bomber strikes Syrian church near Damascus during mass

Published

on

ISIS behind deadly church suicide bombing near Damascus, Syrian interior minister says

NEWYou can now listen to Fox News articles!

A suicide bomber in Syria on Sunday detonated himself inside a church filled with people, state television and a war monitor said.

The explosion in Dweil’a in the outskirts of Damascus took place as people were praying inside the Mar Elias Church. Britain-based war monitor the Syrian Observatory for Human Rights says there were 30 people wounded and killed, but the exact numbers are unclear. Some local media reported that children were among the casualties.

THEY WANT AMERICANS DEAD, TOO — THE THREAT FROM IRAN AND ITS PROXIES

A suicide bomber exploded at the Mar Elias Church on the outskirts of Damascus, Syria, on June 22, 2025. (BAKR ALKASEM/AFP via Getty Images)

Advertisement

The attack was the first of its kind in Syria in years, and comes as Damascus under its de facto Islamist rule is trying to win the support of minorities. As President Ahmad al-Sharaa struggles to exert authority across the country, there have been concerns about the presence of sleeper cells of extremist groups in the war-torn country.

WE CAN’T IGNORE THE DANGER FROM THOSE WHO WANT TO ‘GLOBALIZE THE INTIFADA.’ WE NEED TO TAKE ACTION

Damage done to a church in Syria.

A suicide bomber attacks a church on the outskirts of Damascus, Syria, on June 22, 2025. (BAKR ALKASEM/AFP via Getty Images)

Security forces and first-responders rushed to the church. An eyewitness said in a video widely circulated online that the attacker came in and started to shoot at the people there before detonating an explosive vest he was wearing.

Advertisement
Continue Reading

Technology

Weird-shaped notebooks make me want to write again 

Published

on

Weird-shaped notebooks make me want to write again 

Andru Marino is an audio and video producer at The Verge. “I make videos on our YouTube / TikTok / Instagram channels, and have produced our podcasts like Vergecast, Decoder, and Why’d You Push That Button?” He also keeps a lot of notes, and his latest favorite places to keep them are the Triangle and Sidekick notebooks. I asked him about them.

Where did you first hear about these notebooks?

I don’t really remember when I first saw the Triangle Notebook. It was probably an Instagram ad. I had kept a link to the notebook’s website in a browser tab on my phone for a few months and kept thinking about it.

When did you buy it, and what went into the decision?

I bought it in April, and what really attracted me was how weird it was. Why does the notebook need to be a triangle? Oh, it opens up into a square! Wow, I love that! The main reason I use paper is to doodle, and I thought this shape would inspire me to doodle differently.

Advertisement

And then I saw this company also made another notebook called the Sidekick that basically looks like an L when opened, so it is angled alongside your computer keyboard. That was so wacky to me. So I bought that one too.

What do you like about them?

This seems more like an art experiment than anything. I love objects that make you rethink how they are used. I typically have Post-it notes or a spiral notebook on my desk so I can write something down or doodle during a meeting. The Sidekick doesn’t take up a ton of space on my desk either opened or closed.

The Triangle Notebook is actually great for using on your lap or other unconventional surfaces, as it is pretty sturdy and lays flat on its spine.

Both notebooks also encourage me to use my handwriting more, which was a New Year’s resolution I had.

Advertisement

Is there anything about them that you dislike, or that you think could be improved?

I am not entirely sure if it makes sense to take notes on an L-shaped piece of paper, but that is just what makes the Sidekick different.

The Triangle Notebook could have a few more pages in it. It is nicely bound and sort of expensive ($33), so I would like to get more use out of it. Also it is so long! I don’t know where to store it.

And the pages don’t tear out very easily. I’d love to give someone a note on a weird-shaped piece of paper.

Who would you recommend it to?

Advertisement

I’d recommend the Sidekick to an artist who wants to doodle during meetings — which is why I bought this. But I can also see it working for someone who draws on a tablet and wants to briefly write down some notes about what they are working on.

I don’t know who I would recommend the Triangle Notebook to besides someone who likes weird objects. I’d love to know if someone feels like they do their best work on a triangle-shaped notebook.

You started this by saying you hoped these notebooks would inspire you to doodle differently. Have they?

So far, no. My notes look the same mess as ever, but it has encouraged me to doodle more and write more, so that makes me happy.

Three rows of four varicolored triangles with one in the second row opened to show a notebook.

$33

Triangle-shaped notebook that opens into a square.

Advertisement

Keyboard with L-shaped notebook next to di and a pen below.Keyboard with L-shaped notebook next to di and a pen below.

$24

Notebook shaped like an “L” to wrap around your keyboard.

Continue Reading

Trending