Fake Spotify payment alert wants to trick you into sharing credit card details
A sophisticated phishing campaign impersonating Spotify is targeting New Zealand organisations with realistic billing failure notifications.
This phishing campaign uses fake Spotify payment failure alerts to trick you into providing your business or personal credit card details. Attackers are sending realistic emails claiming that your Premium subscription has been paused and requires an immediate update to avoid service interruption.
This activity was flagged due to its high degree of technical sophistication and its coordinated deployment across multiple New Zealand organisations. The attackers leverage common lifestyle services to catch busy staff off guard during their work routine.
The technical details contain a sharp contradiction: while the emails pass every standard security check—including SPF, DKIM, and DMARC—the sending domain is uma.edu.sv. This is a Salvadoran educational institution with no official connection to Spotify infrastructure, and the reply-to address is routed to a different domain in Spain (code.es).
The surprising detail is the accuracy of the impersonation, featuring perfect Spotify branding and a well-formatted button that leads to a convincing clone of the account overview page. The lure is designed to appear as a legitimate response to an automated billing system error.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Verify Independently: Always log in to your Spotify account directly via the official app or
spotify.comto check billing status. - Check the Sender: Genuine Spotify notifications will only originate from @spotify.com or verified corporate domains.
- Inspect Links: Hover over buttons in unexpected emails to see the actual destination URL before clicking.
- Enable 2FA: Ensure multi-factor authentication is active on all financial and primary email accounts.
See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.


