Spotify is (not) cancelling your subscription
You could receive a fake billing email titled "Your Subscription is Paused" that tries to push you into updating payment details through a convincing but untrusted sender setup.
You may see an email with the subject line "Your Subscription is Paused" that looks like a routine subscription or billing notice. It appears to come from hubspotfree.eu1.hs-send.com and claims there is a problem with your current billing information. It urges you to log in to your account overview, read more details, or update your payment details, which is designed to feel like a normal admin task you should sort out quickly.
What gives it away is that the sender setup does not fully line up, even though some of the usual trust checks appear to pass. The email failed an important sender verification check, which means the claimed sending system was not properly authorised to send on that domain's behalf. On top of that, any reply would go to an outlook.com address rather than back to the apparent sender, which is a strong sign the message is trying to separate the visible sender from where your response actually ends up. The sending domain also lacks the sort of established reputation you would want to rely on for a billing request.
The attacker is after action from you, either a click, a login, a reply, or payment-related details. If you engage, you could be pushed to hand over account credentials, disclose billing information, or start a back-and-forth with the attacker through the different reply address. That can lead to account compromise, fraudulent payment activity, or your business being drawn into a wider phishing chain circulating across NZ.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Review any recent billing or subscription emails with this subject line and confirm whether they came through an authorised business process.
- Check: Hover over links and inspect reply addresses before responding to any billing message, especially if the visible sender and reply path do not match.
- Do not: Click through or enter payment details, passwords, or account information from an email asking you to fix subscription billing urgently.
- Report: Flag the message to your IT provider or security team so they can block the sender pattern and check whether anyone in your organisation engaged with it.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.

