How a Fake Spotify Billing Notice Is Targeting Your Organisation
Threat actors are spoofing Spotify billing notifications to deceive users into surrendering account credentials via phishing pages.
A phishing campaign impersonating Spotify is designed to harvest payment credentials by convincing your staff that a subscription renewal has failed. If acted upon, the embedded link directs recipients to an attacker-controlled page where financial details or account credentials may be captured. Beyond immediate financial exposure, compromised payment information can be leveraged for further fraud, and any credentials entered may be reused across other services your organisation relies upon.
This campaign was identified after a spike in NZ inboxes, with multiple local organisations receiving the same message within a single business day. The rapid distribution across separate organisations in a compressed timeframe indicates an automated sending infrastructure operating at scale, suggesting this is not an opportunistic or isolated attempt.
What makes this campaign particularly deceptive is the combination of a plausible Spotify-branded message with authentication signals that partially satisfy email security checks. Despite an SPF failure — which should indicate the sending domain is not authorised to send on behalf of any legitimate party — DKIM, DMARC, and composite authentication checks all return passing verdicts. This mixed authentication result is a known technique where attackers exploit legitimate email delivery platforms to launder their messages past automated filters, creating a false sense of trustworthiness.
The sender address reveals the infrastructure in use: a HubSpot free-tier sending domain, with the display address constructed to obscure a French commercial domain embedded within it. The link destination is similarly routed through HubSpot's free link-tracking service, which adds a further layer of apparent legitimacy while masking the true destination. This abuse of reputable marketing platforms to deliver credential-harvesting content is a growing pattern, and the technique is effective precisely because the sending and linking infrastructure carries genuine brand recognition that many email security tools are reluctant to penalise.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Verify any subscription renewal notices by logging directly into your Spotify account at spotify.com rather than clicking links in unsolicited emails.
- Scrutinise sender email addresses carefully — legitimate Spotify communications will never come from domains like hubspotfree.eu1.hs-send.com or use mismatched routing addresses.
- Report this phishing email to CERT NZ at CERT NZ via their website at cert.govt.nz or by forwarding the email to report@phishing.cert.govt.nz and forward it to Spotify's official phishing report address (phishing@spotify.com) to help protect other Kiwi users.
- Delete the email immediately without clicking any links or downloading attachments, and empty your deleted items folder to remove it entirely from your inbox.
- Enable multi-factor authentication (MFA) on your Spotify account and any associated payment accounts so that even if your credentials are compromised, unauthorised access is blocked.
See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.


