Spotify’s Music Catalog Leaked in Massive Data Breach

spotify music catalog leaked

Spotify music catalog leaked after a large-scale scrape tied to Anna’s Archive spilled massive Spotify metadata—and claims of audio-file access—into torrent-ready packages, prompting Spotify to disable accounts and add new safeguards.​

What leaked and when

Reports published around Dec. 21–22, 2025 describe a bulk “preservation/archive” release that includes Spotify track metadata at very large scale and claims access to a huge portion of Spotify-hosted audio files. The packages described total roughly 300TB and include figures such as 256 million rows of track metadata and about 86 million audio files, with releases staged (metadata first, audio later). Multiple reports also note the scrape largely reflects availability up to around July 2025, meaning newer additions may be absent.​

Timeline snapshot

Date (2025) Reported development Why it matters
Dec. 21 The archive/scrape announcement and early distribution of large Spotify metadata packages begins circulating widely. ​ Marks the point the dataset becomes broadly mirrorable via peer-to-peer sharing. ​
Dec. 21–22 Reporting crystallizes the headline numbers: ~300TB total, ~256M metadata rows, and claims of ~86M audio files. ​ Helps rightsholders and researchers estimate scope and prioritize response. ​
Dec. 22 Spotify’s response emphasizes disabling accounts involved in scraping and adding safeguards. ​ Signals mitigation and active monitoring, while investigation continues. ​

How it happened (and what “scraping” means here)

Spotify’s public-facing catalog data can be collected at scale through “scraping,” a form of automated data collection that can overwhelm controls if a party uses many accounts and techniques to evade detection. In this incident, Spotify stated it “identified and disabled” accounts involved in “unlawful scraping,” and said it implemented new safeguards aimed at these “anti-copyright attacks.” Separate reporting also describes unauthorized tactics used to reach some audio files by circumventing DRM (digital rights management), alongside scraping of public metadata.​

Importantly, the dataset described in reports is framed primarily as catalog/content data (track metadata and claimed audio files), not a dump of Spotify customer payment information. Spotify’s own consumer guidance also stresses that “breaches on other services” can lead to Spotify account logins when people reuse passwords, even when Spotify says its “platform and user records are secure.”​

What Spotify says (and what it doesn’t)

Spotify’s public response, as quoted in reporting and statements, focuses on enforcement and mitigation: disabling suspicious accounts, adding safeguards, and monitoring for suspicious behavior. Spotify also positions the incident as a piracy/rights-protection problem, stating it has “stood with the artist community against piracy” and is working with industry partners to protect creators. At the same time, current public reporting remains fluid about the precise boundary between “public metadata scraped at scale” versus “audio files accessed by bypassing DRM,” and how much of the claimed audio dataset is actually obtainable by the public right now.​

On the user-security side, Spotify’s official help guidance continues to frame many “hacked account” experiences as credential-reuse fallout from breaches elsewhere, listing warning signs like unexpected email changes, playlist changes, and logins you don’t recognize. That distinction matters because a catalog/content leak primarily impacts rightsholders and platform integrity, while account-takeover waves primarily impact listeners and can happen even without a platform-wide database theft.​

What was reportedly exposed vs. typical account-takeover data

Category What this incident is described as Typical user impact
Catalog metadata Large-scale tables (hundreds of millions of track rows) shared in bulk packages. ​ Enables copying, indexing, and potential downstream misuse (e.g., mass mirroring, analytics, or identification of catalog structure). ​
Audio files (claimed) Reports describe tens of millions of audio files and ~300TB total archive size, with phased release plans. ​ Heightened piracy risk and potential licensing/rights disputes if widely distributed. ​
Listener accounts Spotify’s help guidance emphasizes credential reuse from other breaches can still lead to account compromise without Spotify’s databases being “breached.” ​ Users may see unauthorized logins, playlist changes, or subscription changes; Spotify advises monitoring for these signs. ​

Why this matters for artists, labels, and the music business

If large-scale catalog metadata is mirrored broadly, it can lower the friction for piracy ecosystems to organize, identify, and distribute content—even when the underlying audio is hosted elsewhere or protected by DRM. The claims about audio-file access are especially sensitive because they imply a path around DRM protections that, if repeatable, could be reused beyond this single release. The scale described—hundreds of terabytes—also changes the enforcement reality: once enough mirrors exist, takedowns become far less effective than prevention and source-side controls.​

The incident also lands at a moment when music rightsholders are already navigating broader pressures: AI-related copying concerns, escalating anti-piracy enforcement, and platform accountability debates. Even if most listeners never download torrents, a widely mirrored catalog dataset can still create downstream business risks—like facilitating counterfeit uploads, impersonation, or rapid rehosting by piracy services.​

What users should do now (practical steps)

Spotify’s own guidance for suspected account compromise focuses on spotting unauthorized changes (email, playlists, subscription, unexpected playback) and acting quickly if those signs appear. Because credential reuse is a common driver of account takeovers, tightening password hygiene and enabling stronger login protections reduces risk even when a user isn’t directly affected by this catalog leak. If unusual activity is seen, treat it as an account-security issue (not necessarily proof that Spotify’s internal user database was stolen) and follow Spotify’s official support steps.​

For artists/labels/publishers, the near-term priority is monitoring: search for newly appearing mirrors, suspicious re-uploads, and unusually complete “Spotify library” bundles that match the described dataset, then coordinate enforcement through distribution partners. Internally, stakeholders will likely press for clearer technical disclosure on what was accessed (public metadata only vs. audio retrieval path), what controls failed, and what new safeguards were deployed.​

Final thoughts

This Spotify music catalog leak is being characterized as a large-scale scraping-and-distribution event with unusually large scope claims, and Spotify says it has already disabled accounts involved and rolled out additional safeguards. The biggest open questions are practical: how much of the claimed audio archive becomes publicly obtainable, and whether the reported DRM-circumvention method can be repeated or has been closed. For most listeners, the most immediate risk remains account takeover via reused passwords, and Spotify’s official “hacked account” guidance remains the clearest action framework if anything looks wrong.​


Subscribe to Our Newsletter

Related Articles

Top Trending

benefits of reading aloud
Why Reading Aloud Beats Apps for Brain Health and Literacy
Best VR and AR Apps for Education
9 Best VR and AR Apps for Education
How to Price a SaaS Product Models
How to Price a SaaS Product: Models, Psychology, and Mistakes
Product Analytics vs Web Analytics
Product Analytics vs Web Analytics: What SaaS Teams Actually Need
The Future of All-in-One AI Creative Platforms
The Future of All-in-One AI Creative Platforms

Technology & AI

How to Price a SaaS Product Models
How to Price a SaaS Product: Models, Psychology, and Mistakes
Product Analytics vs Web Analytics
Product Analytics vs Web Analytics: What SaaS Teams Actually Need
The Future of All-in-One AI Creative Platforms
The Future of All-in-One AI Creative Platforms
Personal Knowledge Management
What Is Personal Knowledge Management and Do You Need It?
History of AI Milestones
10 Milestones That Defined the History of AI

GAMING

Complete Guide on Game Programgeeks
Game Programgeeks: A Complete Guide on PC, Game Dev, and Tech
Online Color Game Philippines
Online Color Game Philippines: What Every Beginner Should Know Before Playing
Ways to Reduce Game Development Costs
12 Ways Studios Cut Game Development Costs
NFT game development cost
How Much Does NFT Game Development Cost? A Realistic Budget Breakdown
Reasons Why You No Longer Need the Best Roblox AI Scripter
Forget Best Roblox AI Scripter: 10 Reasons Why You No Longer Need It

Business & Marketing

Low Minimum Order Merchandise
Big Impact, Small Batch: The Strategic Power of Low Minimum Order Merchandise
A side-by-side illustration exposing link building myths by contrasting budget lost on spammy backlinks with long-term SEO growth to help marketers protect their investment.
Stop Wasting Money: 10 Link Building Myths Ruining Your ROI
Circular infographic diagram breaking down key elements of a project charter for small teams, including scope, vision, and risks
What Is a Project Charter and Why Small Teams Skip It at Their Peril
How to Run a Project
How to Run a Project Without Using Any Project Management Softwares
A photo of a laptop on a wooden desk displaying a complex digital data visualization of a marketing channel network where green nodes indicate success and one highlighted red path visualizes the clear signs to fire a marketing channel that is underperforming. This image helps viewers grasp the data necessary for auditing channel viability.
Stop Wasting Ad Spend: 9 Signs to Fire a Marketing Channel

EdTech & E-Learning

Best VR and AR Apps for Education
9 Best VR and AR Apps for Education
Orthographic Mapping
What Is Orthographic Mapping? Why Words Stick: A Practical Guide
Best Study Apps for Exam Preparation
10 Best Study Apps for Exam Preparation
what is subitizing
What Is Subitizing? The Hidden Math Skill Your Child Uses Every Day
How to Find That Your Child Is Guessing Letters
Is Your Child Guessing Letters? How to Tell and Fix It

Software & Apps

Best Study Apps for Exam Preparation
10 Best Study Apps for Exam Preparation
Best Distraction Blocker Apps and Extensions
9 Best Distraction Blocker Apps and Extensions
Best Calendar Apps for Different Ways of Working
8 Best Calendar Apps That Leave Default Tools Behind
Best Productivity Apps
10 Best Productivity Apps for Linux to Supercharge Your Workflow
Best Influencer Marketing Platforms
9 Best Influencer Marketing Platforms in 2026: Features, Pricing & Comparison