A pirate archivist group known as Anna's Archive has allegedly scraped and downloaded a significant portion of Spotify's music library, amounting to approximately 300 terabytes of data. This collection includes around 86 million audio files, which represents about 37% of Spotify's total music catalog but covers nearly all of the platform's most-listened tracks. The group also accessed 256 million rows of metadata, and both the music files and metadata have been distributed via torrent sites, raising major concerns about copyright infringement and data security.
Spotify has acknowledged the incident and confirmed that a third party used illicit tactics to circumvent digital rights management (DRM) protections and scrape both public metadata and some audio files. The company is actively investigating the breach, which has drawn attention due to the scale of the data involved and the public availability of the metadata through Anna’s Archive. The incident highlights ongoing challenges in protecting digital content from large-scale unauthorized access and distribution, especially by groups motivated by preservation or hacktivist ideologies.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
In response to the scraping operation, Spotify said it disabled the accounts used in the activity, implemented new safeguards, and continued monitoring for suspicious behavior. It also said it was working with partners to protect artists and deter further distribution.
Spotify acknowledged that a third party scraped public metadata and accessed some audio files by circumventing DRM, while stating that no user data or business systems were compromised. The company said it was actively investigating the incident.
The group announced and began distributing the scraped Spotify dataset through bulk torrents and staged BitTorrent releases. Public reporting said metadata was already available, while audio files were being released in phases with popular tracks prioritized.
Anna's Archive said it used large-scale scraping of Spotify metadata and circumvention of DRM protections to collect about 256 million rows of metadata and roughly 86 million audio files, totaling around 300 TB. The archive said the collection was intended as an open music preservation project and that the audio set covered the most-listened portions of Spotify's catalog.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
10 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemalwarebytes.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcetomshardware.com
Open sourcetherecord.media
Open sourcetechxplore.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.