A journalist showed how easy it is to upload AI-generated songs onto a real artist’s official Spotify page by abusing weak identity checks in digital music distribution. By claiming to be the band during a distributor signup/upload process, the uploader can publish fake tracks to major streaming services and collect royalties, damaging the artist’s reputation and confusing fans.
How the Attack Worked
A journalist demonstrated how easy it is to publish AI-generated songs onto a real band's official Spotify page by exploiting weak identity checks in the digital music distribution pipeline. During the upload process with a distributor, the journalist simply typed in the name of an existing band. The distributor's system auto-matched that name to the band's verified profile. From there, the only barrier was a series of self-attestation checkboxes confirming the uploader was authorized to release music under that name. No proof of identity or rights ownership was required. Within a short time, the fake track appeared on the band's official page across multiple streaming platforms.
Why It Succeeded
The attack succeeded because distributor onboarding workflows lean heavily on trust rather than verification. Checkboxes asking uploaders to confirm they are authorized are not backed by any identity or rights confirmation process. This gap lets anyone who knows a band's name attempt to publish content to that band's official presence. The problem is compounded for artist profiles that are not actively managed, since there is no one watching for unauthorized releases or catching them quickly after they go live.
Impact on Artists and Platforms
This kind of impersonation can divert royalties away from the real artist and toward the fraudulent uploader. It also risks damaging the artist's reputation, since fans may associate low-quality or misleading AI-generated tracks with the band without knowing the content was never authorized. Streaming platforms and distributors have acknowledged that detection is difficult at scale, citing very high daily upload volumes and manual review processes that cannot keep pace, along with the added complexity of artists legitimately changing labels or distributors over time.
What to Watch For and How to Build Resistance
Defenders across the music industry, including artists, label operations, content moderation teams, and distribution managers, should take note of the following:
- Treat any onboarding process built on self-attestation as a risk signal rather than a safeguard, and push for verification and approval gates before content reaches official pages.
- Actively monitor and claim artist profiles, since unattended pages are easier targets for hijacking.
- Use pre-release approval features where distributors or platforms offer them, allowing artists to review and approve releases before they go live.
- Establish a clear, fast escalation and takedown process with distributors and streaming services, given that manual review at scale is inconsistent and slow.
The underlying weakness here is not sophisticated hacking but a reliance on unverified claims during account and catalog management, a pattern relevant well beyond the music industry wherever platforms allow self-reported identity to control access to sensitive assets.
Key findings
- An uploader can publish music to a real artist’s official pages by entering the artist name during a distributor upload and selecting the matched profile.
- The distributor workflow relies heavily on self-attestation (checkboxes) without verifying authorization, enabling impersonation.
- This can divert royalties to the fraudster and harm the artist’s reputation by associating them with low-quality or misleading content.
- Less actively managed artist profiles are described as especially vulnerable, increasing risk for smaller or deceased artists.
- Streaming platforms and distributors acknowledge scale and detection/verification challenges (e.g., large daily upload volumes, unreliable AI detection).
Who’s being targeted
- Commonly targeted roles: Artists/Bands, Music label operations, Content moderation/catalog teams, Customer support/trust & safety, Digital distribution managers.
- Affected industries: Music and entertainment, Media/streaming platforms, Independent artists/labels.
- Attack channels: website.
- Impersonated: A real band/artist (e.g., Lathe of Heaven).
Red flags to watch for
- Distributor only asks the uploader to check ‘authorized’ boxes, with no proof of identity or rights ownership verification
- Auto-matching to an existing verified artist page based solely on typed name
- Release appears on multiple platforms within a day, even though the real artist did not submit it
Frequently asked questions
How did the uploader get music onto a real artist's Spotify page?
By typing the artist's name into a distributor's upload form, the distributor auto-matched an existing verified profile, and the uploader simply checked boxes claiming authorization without any identity verification.
Why didn't the distributor catch the impersonation?
The workflow relies on self-attestation checkboxes rather than proof of identity or rights ownership, so anyone typing the correct band name could be matched to the real profile.
Which artists are most at risk of this kind of hijack?
Profiles that are not actively managed are described as especially vulnerable, which increases risk for smaller or deceased artists whose pages get little attention.
What can artists and labels do to prevent this?
Actively monitor and claim official profiles, use pre-release approval controls where offered, and establish a fast takedown process with distributors and streaming platforms.
Read the video transcript
“When Distrokid asked for my artist name, I typed in Lathe of Heaven.” And that AI track went onto the real band’s Spotify page. The trick is stupidly simple: type a real band name, click the auto-matched profile, tick a few ‘I’m authorized’ boxes… and the distributor ships your AI song to Spotify and others. No ID, no proof, nothing. Here’s the scary part: for less-managed or older artist profiles, this junk can just appear overnight. Fans see it on the official page, royalties go to the imposter, and your reputation takes the hit. Your move: make sure every official artist profile you touch has pre-release approval turned on, so nothing goes live on that page until someone on your team clicks approve.