Anna’s Archive claims it obtained metadata for around 256 million tracks and audio files for roughly 86 million songs, totaling close to 300 TB. Reportedly, this represents about 99.9% of Spotify’s catalog and roughly 99.6% of all streams.
Spotify says it has “identified and disabled the nefarious user accounts that engaged in unlawful scraping” and implemented new safeguards. From a security perspective, this incident is a textbook example of how scraping can escalate beyond “just metadata” into industrial‑scale content theft.
Read more…
Source: Malwarebytes Labs
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Ransomware gangs skip the CEO, head straight for the 40-something IT manager
August 9, 2026
Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data suggests today’s ransomware crews have ...
- Intrusion at US healthcare software provider puts 3.8M people’s data at risk
August 7, 2026
A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year. The attack dates to last October, when Ohio-based medical software maker Unlimited Technology Systems (UTS) detected someone poking around its commercial datacenter. ...
- Swiss government says SharePoint-linked data breach affected hundreds of accounts
August 7, 2026
Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation. In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal ...
- Anthropic’s Mythos AI used social engineering to target real people
August 6, 2026
Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged. AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol when it detected ...
- Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
August 6, 2026
It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known ...
- How legitimate cloud platforms enable phishers to bypass MFA
August 4, 2026
Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky researchers have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub ...
