Hacktivists operating under the name "Anna's Archive" scraped Spotify's music library and published the platform's metadata online. The group claimed to have collected 256 million rows of track records and 86 million audio files, amounting to approximately 300 terabytes of metadata, though only metadata—not actual music files—has been released as of December 21. Anna's Archive, which typically focuses on archiving books and academic papers, described this action as part of a broader mission to preserve cultural knowledge, positioning the Spotify data scrape as an effort to build a comprehensive music archive.
Spotify has not reported the release of any actual audio files, and the hacktivists have stated that their intent is preservation rather than piracy. The incident highlights the ongoing risks of large-scale data scraping and the exposure of proprietary metadata, which could have implications for intellectual property and user privacy. An investigation into the unauthorized access is reportedly underway, but no further details about Spotify's response or potential impact on users have been disclosed.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
A major data leak involving Buenos Aires-based data broker SudamericaData exposed sensitive information belonging to millions of people in Argentina.
Nissan reported a third-party data breach stemming from Red Hat's compromised GitLab instance that exposed customer information. The company said financial data was not affected.
Hacktivist group Anna's Archive scraped and published Spotify metadata, exposing 256 million track records and metadata for 86 million audio files. No music files themselves were released.
Ukrainian national Artem Stryzhak pleaded guilty to participating in the Nefilim ransomware campaign, while the group's alleged leader remained at large.
The U.S. Department of Justice indicted 54 members of the Tren de Aragua gang over alleged ATM jackpotting attacks using Ploutus malware.
Authorities in Nigeria arrested the suspected operator of the RaccoonO365 phishing service, which was used to target Microsoft 365 accounts globally.
Interpol coordinated Operation Sentinel against cybercrime in Africa, resulting in 574 arrests and the seizure of $3 million in illicit funds tied to schemes including business email compromise and ransomware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.