You have had a Spotify account for years and your credit card is linked for the monthly payments. When an email arrives telling you that your payment couldn’t be processed you are not surprised as the expiry date on the card is soon.“We encountered an issue while processing your recent payment,” it says. “To keep your access active and avoid interruption, please review and update your information.”All you need to do, according to the email, is click the button to “update payment method”. “This only takes a moment and helps ensure uninterrupted access to your account and services.”When you click the link you are taken to what you think is Spotify and you are asked to log in and then enter your new card details, your address and phone number.Unfortunately, the email is not from Spotify and the link takes you to a cloned scam site that collects your login, personal and payment details, which criminals then immediately try to use for online purchases.“I saw the email on my phone while I was having a conversation and watching the tennis so just tapped the link to update the card without thinking about it,” said Barry*, who contacted the Guardian after falling victim to the scam. “I was immediately hit with a suspicious credit card check for ‘Tm Connect’ followed by a Ticketmaster transaction in US$ for a sum equivalent to £469.22, which I declined.”“I never thought I would be the kind of person to fall for a scam and I am exactly the kind of person to judge those who do. Luckily I use virtual credit cards for online subscriptions, so I could quickly cancel the card and change my unique Spotify password to limit the damage.”What it looks likeThe scam email looks convincing at a glance, but look closely and you will spot inconsistencies that give the game away, such as an unknown sender and lower-case subject. Composite: Samuel Gibbs/The GuardianThe fake emails are a convincing replica of Spotify’s email notifications, including the company’s logo, the correct colour scheme and MySpotify name on the email.Small telltale signs show the email is not legitimate, such as not including the tier of your Spotify subscription and using all lower-case letters for the email subject line.But the biggest give away is that the email does not come from an @spotify.com address and clicking the button takes you to a random site not using the spotify.com domain.The site you end up at also looks convincing on first look, but the URL is not a Spotify.com domain. Composite: Samuel Gibbs/The GuardianWhat to doIf you receive an email like this, even if you are expecting to change your payment details in the near future, do not click the links. Go direct to Spotify and log in on Spotify.com to make any changes when necessary.“Spotify takes the protection of users very seriously,” said a company spokesperson. “We will never ask for personal information via email, including payment details, passwords, or government-issued identification numbers. We will also never request payments through third-party services or ask users to download files or software from our emails.”Check the email headers and URL links to ensure they are from the Spotify.com domain. Report the fraudulent emails to your email provider and forward it to Spotify at spoof@spotify.com.“If anything about the message seems unusual, do not respond, click any links or download any attachments. Users who believe they may have already engaged with a suspicious email should immediately reset their Spotify password and review their account for any unauthorised changes,” Spotify said.If you believe your payment details have been compromised, contact your bank immediately.Spotify has various tools to recover accounts, lost playlists and other data. You can prove your ownership of the account with a screenshot of a Spotify receipt or bank statement.* Name has been changed
‘I never thought I’d fall for a scam’: the fake Spotify emails that put you at risk of fraud
Full Article
Original Source
Read the full article at Theguardian →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.