Your Spotify subscription is on hold!
A coordinated campaign impersonating Spotify is targeting New Zealand organisations via high-reputation marketing infrastructure.
A sophisticated phishing campaign has been detected impersonating Spotify, specifically utilizing 'Account on Hold' and 'Payment Unsuccessful' lures. The messages originate from the infrastructure of a global marketing platform (hubspotfree.eu1.hs-send.com), which allows the campaign to bypass many traditional reputation-based security filters. Technical analysis indicates that while the sender domain passes DKIM and DMARC checks, it failed SPF authentication, highlighting a deliberate attempt to leverage high-reputation delivery nodes for malicious purposes.
The clinical indicator of fraud in this campaign is the 'Reply-To' mismatch. Although the message appears to be from a legitimate service domain, all technical replies are directed to an unrelated domain (mail.pipefy.com). This 'Reply-Chain Hijack' technique is designed to divert user interactions toward attacker-controlled communication channels, bypassing official organisational oversight.
The email body employs high-fidelity Spotify branding, including accurate color palettes and logo placement, to create a sense of financial urgency. Users are prompted to 'Update Payment Information' via links that lead to credential harvesting portals. This campaign is particularly effective because it targets the common business workflow of managing SaaS subscriptions, relying on the high volume of legitimate marketing mail typically received by organisations to remain undetected.
Organisations are advised to treat any unsolicited subscription alerts with clinical skepticism. Legitimate billing and account status updates for Spotify should be verified strictly through the official spotify.com portal or the mobile application. Enforcing strict 'First Contact' safety tips and encouraging users to utilize the 'Report Phishing' mechanism remain the most effective methods for refining tenant-level security against these high-reputation infrastructure abuses.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Verify account status strictly via official mobile applications or the official spotify.com portal.
- Monitor for 'Reply-To' mismatches in organisational mail flow to identify identity-based probes.
- Implement 'Safe Links' policies to intercept and rewrite URLs from high-volume marketing nodes.
- Educate staff on the risks of interacting with unsolicited subscription renewal alerts.
See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.


