Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers
Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

Key points
- Criminals are sending fake Spotify emails that claim a subscriber's payment has failed, then direct victims to a cloned website that steals personal and financial details.
- The scam exploits a routine anxiety: many subscribers know their card is close to expiry, making the fake warning feel plausible.
- The copycat site collects login credentials (your username and password), personal information, and full payment card details.
- Anyone who entered details on such a site should contact their bank and change their Spotify password immediately.
Your Spotify subscription renews quietly every month. You barely notice it until, one day, an email arrives saying the payment did not go through.
The message looks right. The logo looks right. It says: "We encountered an issue while processing your recent payment. To keep your access active and avoid interruption, please review and update your information." Your card does expire soon. You click the link.
That is exactly what criminals are counting on.
What is actually happening here?
The email is a phishing message, meaning a fake email crafted to impersonate a trusted brand and trick you into handing over sensitive information. The link inside does not go to Spotify. It goes to a cloned site, a near-identical copy of Spotify's login or payment page, built by criminals to harvest whatever you type into it.
First reported by The Guardian, the scam works because it targets a very specific, very believable moment: the window when a subscriber's card is approaching its expiry date. That timing is not accidental. Fraudsters know that a payment-failure message sent during this window will feel routine rather than suspicious.
Once you type in your email address, password, and card number, the criminals have everything they need. They can drain a linked bank account, run up charges on the card, or sell the details in bulk to other fraudsters.
Should I be worried if I got one of these emails?
Yes, if you clicked the link and entered any details, act now. Call your bank or card provider and tell them your card details may have been stolen. Most banks can freeze the card and issue a new one within days.
Change your Spotify password straight away. If you use the same password on any other site, including email accounts, change those too. Reusing passwords across sites is common, and criminals know it.
If you only opened the email but did not click or type anything, you are almost certainly fine.
How do I spot a fake payment email?
A few quick checks catch most of these scams before any damage is done.
Look at the sender's email address, not just the display name. A genuine Spotify email comes from a @spotify.com domain. Anything with extra words, hyphens, or a different domain altogether is a red flag.
Before clicking any link, hover your mouse over it (on a phone, press and hold) and look at the web address that appears. If it does not start with spotify.com, do not click it.
When in doubt, skip the email entirely and go directly to Spotify's website by typing the address into your browser yourself. Check your payment details there. If there really is a problem, you will see it logged in your account.
Common questions
Can Spotify tell me if an email I received was real?
Yes. Spotify has a support page where you can check whether a message genuinely came from them. You can also forward suspicious emails to their security team.
What if I already entered my details?
Contact your bank immediately to report a potential card compromise and request a new card. Change your Spotify password and any other account that shares that password, starting with your primary email account.



