Anna’s Archive claims it obtained metadata for around 256 million tracks and audio files for roughly 86 million songs, totaling close to 300 TB. Reportedly, this represents about 99.9% of Spotify’s catalog and roughly 99.6% of all streams.
Spotify says it has “identified and disabled the nefarious user accounts that engaged in unlawful scraping” and implemented new safeguards. From a security perspective, this incident is a textbook example of how scraping can escalate beyond “just metadata” into industrial‑scale content theft.
Read more…
Source: Malwarebytes Labs
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing
September 1, 2026
Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as “OAuth consent phishing.” Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted ...
- P&O Ferries data blunder as it sends out passengers’ personal details by text message
August 31, 2026
P&O Ferries was hit by a data breach after mistakenly sending out a full list of passengers’ personal details by text message this morning, we can reveal. A blunder saw the details of 432 passengers travelling on the 12pm P&O ferry from Calais to Dover sent as an attachment in a customer services text message. It is ...
- ValleyRAT masquerading as adware
August 31, 2026
Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the ...
- Healthcare data breach exposes 3.75M patient records
August 30, 2026
Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million ...
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion
August 28, 2026
Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply ...
- Millions of UK airport customer details accessed in major cyberattack
August 27, 2026
A cyber security breach targeting three major UK airports has led to the personal data of around 8.7 million customers being accessed, operator Manchester Airport Group (MAG) has confirmed. The group, which oversees Manchester Airport, London Stansted and East Midlands Airport, assured the public that “at no point has passenger safety or aviation security been compromised”, adding that no payment or banking details ...
