AI Scammer Hijacks Band’s Spotify via Distributor

404 Media · Low sophistication
Last updated September 18, 2026

A journalist showed how easy it is to upload AI-generated songs onto a real artist’s official Spotify page by abusing weak identity checks in digital music distribution. By claiming to be the band during a distributor signup/upload process, the uploader can publish fake tracks to major streaming services and collect royalties, damaging the artist’s reputation and confusing fans.

How the Attack Worked

A journalist demonstrated how easy it is to publish AI-generated songs onto a real band's official Spotify page by exploiting weak identity checks in the digital music distribution pipeline. During the upload process with a distributor, the journalist simply typed in the name of an existing band. The distributor's system auto-matched that name to the band's verified profile. From there, the only barrier was a series of self-attestation checkboxes confirming the uploader was authorized to release music under that name. No proof of identity or rights ownership was required. Within a short time, the fake track appeared on the band's official page across multiple streaming platforms.

Why It Succeeded

The attack succeeded because distributor onboarding workflows lean heavily on trust rather than verification. Checkboxes asking uploaders to confirm they are authorized are not backed by any identity or rights confirmation process. This gap lets anyone who knows a band's name attempt to publish content to that band's official presence. The problem is compounded for artist profiles that are not actively managed, since there is no one watching for unauthorized releases or catching them quickly after they go live.

Impact on Artists and Platforms

This kind of impersonation can divert royalties away from the real artist and toward the fraudulent uploader. It also risks damaging the artist's reputation, since fans may associate low-quality or misleading AI-generated tracks with the band without knowing the content was never authorized. Streaming platforms and distributors have acknowledged that detection is difficult at scale, citing very high daily upload volumes and manual review processes that cannot keep pace, along with the added complexity of artists legitimately changing labels or distributors over time.

What to Watch For and How to Build Resistance

Defenders across the music industry, including artists, label operations, content moderation teams, and distribution managers, should take note of the following:

  • Treat any onboarding process built on self-attestation as a risk signal rather than a safeguard, and push for verification and approval gates before content reaches official pages.
  • Actively monitor and claim artist profiles, since unattended pages are easier targets for hijacking.
  • Use pre-release approval features where distributors or platforms offer them, allowing artists to review and approve releases before they go live.
  • Establish a clear, fast escalation and takedown process with distributors and streaming services, given that manual review at scale is inconsistent and slow.

The underlying weakness here is not sophisticated hacking but a reliance on unverified claims during account and catalog management, a pattern relevant well beyond the music industry wherever platforms allow self-reported identity to control access to sensitive assets.

Key findings

  • An uploader can publish music to a real artist’s official pages by entering the artist name during a distributor upload and selecting the matched profile.
  • The distributor workflow relies heavily on self-attestation (checkboxes) without verifying authorization, enabling impersonation.
  • This can divert royalties to the fraudster and harm the artist’s reputation by associating them with low-quality or misleading content.
  • Less actively managed artist profiles are described as especially vulnerable, increasing risk for smaller or deceased artists.
  • Streaming platforms and distributors acknowledge scale and detection/verification challenges (e.g., large daily upload volumes, unreliable AI detection).

Who’s being targeted

  • Commonly targeted roles: Artists/Bands, Music label operations, Content moderation/catalog teams, Customer support/trust & safety, Digital distribution managers.
  • Affected industries: Music and entertainment, Media/streaming platforms, Independent artists/labels.
  • Attack channels: website.
  • Impersonated: A real band/artist (e.g., Lathe of Heaven).

Red flags to watch for

  • Distributor only asks the uploader to check ‘authorized’ boxes, with no proof of identity or rights ownership verification
  • Auto-matching to an existing verified artist page based solely on typed name
  • Release appears on multiple platforms within a day, even though the real artist did not submit it
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the uploader get music onto a real artist's Spotify page?

By typing the artist's name into a distributor's upload form, the distributor auto-matched an existing verified profile, and the uploader simply checked boxes claiming authorization without any identity verification.

Why didn't the distributor catch the impersonation?

The workflow relies on self-attestation checkboxes rather than proof of identity or rights ownership, so anyone typing the correct band name could be matched to the real profile.

Which artists are most at risk of this kind of hijack?

Profiles that are not actively managed are described as especially vulnerable, which increases risk for smaller or deceased artists whose pages get little attention.

What can artists and labels do to prevent this?

Actively monitor and claim official profiles, use pre-release approval controls where offered, and establish a fast takedown process with distributors and streaming platforms.

Read the video transcript

“When Distrokid asked for my artist name, I typed in Lathe of Heaven.” And that AI track went onto the real band’s Spotify page. The trick is stupidly simple: type a real band name, click the auto-matched profile, tick a few ‘I’m authorized’ boxes… and the distributor ships your AI song to Spotify and others. No ID, no proof, nothing. Here’s the scary part: for less-managed or older artist profiles, this junk can just appear overnight. Fans see it on the official page, royalties go to the imposter, and your reputation takes the hit. Your move: make sure every official artist profile you touch has pre-release approval turned on, so nothing goes live on that page until someone on your team clicks approve.

Similar attacks

AI “Agents” Flood Inboxes With Spam Pitches

AI “Agents” Flood Inboxes With Spam Pitches

The article describes real-world examples of unsolicited emails that claim to be sent by “AI agents,” pitching services, interviews, coverage, and paid work. It includes specific subject lines and message excerpts that show a repeatable workflow: automated outreach that tries to prompt recipients…

September 15, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake Céline Dion Tickets Trap Fans on Facebook

Fake Céline Dion Tickets Trap Fans on Facebook

Scammers are approaching Céline Dion fans on Facebook and steering them into paying for “tickets” outside official resale channels. Victims may even receive a real-looking Ticketmaster transfer link, but scammers send the same ticket to multiple buyers so only the first person scanned at the venue…

July 15, 2026
ChatGPT-Enabled Scam Network Disrupted

ChatGPT-Enabled Scam Network Disrupted

A Cambodia-based scam network used ChatGPT to run multiple social-engineering schemes at once, including romance scams that pivoted into fake crypto/gold investments. The same operators also posed as online gambling reps offering fake winnings and as law enforcement demanding “fines,” using forged…

August 27, 2026
Phone Scammers Used Fear to Sell €4,000 of Fake Filters

Phone Scammers Used Fear to Sell €4,000 of Fake Filters

A real phone scam convinced an elderly woman that her drinking water was unsafe and pressured her into buying four overpriced “water filters,” costing about €4,000. The article also describes common Portugal-targeted scams, including “Hi Mum/Hi Dad, I lost my phone” money-transfer fraud and SMS…

August 14, 2026
TikTok Resin Art “DM to Order” Scam

TikTok Resin Art “DM to Order” Scam

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct messages (and sometimes off-platform), they request deposits or full payment and then disappear, or they try to extract personal/banking…

July 24, 2026