Back to The Local Vocal
The Local VocalMedium
PhishingSpotify
Email
Medium risk PhishingEncountered ViaEMAIL 4 August 2026
RegionOtago

Your Spotify subscription is on hold!

A coordinated campaign impersonating Spotify is targeting New Zealand organisations via high-reputation marketing infrastructure.

A sophisticated phishing campaign has been detected impersonating Spotify, specifically utilizing 'Account on Hold' and 'Payment Unsuccessful' lures. The messages originate from the infrastructure of a global marketing platform (hubspotfree.eu1.hs-send.com), which allows the campaign to bypass many traditional reputation-based security filters. Technical analysis indicates that while the sender domain passes DKIM and DMARC checks, it failed SPF authentication, highlighting a deliberate attempt to leverage high-reputation delivery nodes for malicious purposes.

The clinical indicator of fraud in this campaign is the 'Reply-To' mismatch. Although the message appears to be from a legitimate service domain, all technical replies are directed to an unrelated domain (mail.pipefy.com). This 'Reply-Chain Hijack' technique is designed to divert user interactions toward attacker-controlled communication channels, bypassing official organisational oversight.

The email body employs high-fidelity Spotify branding, including accurate color palettes and logo placement, to create a sense of financial urgency. Users are prompted to 'Update Payment Information' via links that lead to credential harvesting portals. This campaign is particularly effective because it targets the common business workflow of managing SaaS subscriptions, relying on the high volume of legitimate marketing mail typically received by organisations to remain undetected.

Organisations are advised to treat any unsolicited subscription alerts with clinical skepticism. Legitimate billing and account status updates for Spotify should be verified strictly through the official spotify.com portal or the mobile application. Enforcing strict 'First Contact' safety tips and encouraging users to utilize the 'Report Phishing' mechanism remain the most effective methods for refining tenant-level security against these high-reputation infrastructure abuses.

Email authorisation
SPF
fail
DKIM
pass
DMARC
pass
COMPAUTH
pass
Domain authentication
Sender / From domain
hubspotfree.eu1.hs-send.com
Reply-To domain
mail.pipefy.com ⚠ mismatch
Email Sample
Email Sample screenshot
Domain Reputation
Abuse score
85/ 100High abuse
ISP (Internet Service Provider)
HubSpot, Inc.
Function:Marketing Delivery Infrastructure
Reputation:Flagged / Reputation Abuse
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Verify account status strictly via official mobile applications or the official spotify.com portal.
  • Monitor for 'Reply-To' mismatches in organisational mail flow to identify identity-based probes.
  • Implement 'Safe Links' policies to intercept and rewrite URLs from high-volume marketing nodes.
  • Educate staff on the risks of interacting with unsolicited subscription renewal alerts.
Spotify logo
Is it real?
Got an email from Spotify?

See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing