Michael Smith of Cornelius, North Carolina, pleaded guilty in federal court in the Southern District of New York to conspiracy to commit wire fraud after prosecutors said he used artificial intelligence to generate hundreds of thousands of songs and then inflated their popularity with automated bot accounts on major music streaming platforms. Authorities said the operation ran from 2017 through 2024, using bulk email registrations, scripted playback, and cloud infrastructure to create fake listeners and stream Smith’s catalog billions of times while spreading activity across many tracks to avoid detection.
Prosecutors said the scheme diverted royalty payments from legitimate artists and rights holders and generated more than $8 million in fraudulent proceeds, with some reports putting the total at more than $10 million. Smith agreed to forfeit $8,091,843.64, and he now faces sentencing on July 29, 2026; the FBI investigated the case and the Southern District of New York’s Complex Frauds and Cybercrime Unit is prosecuting it.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Following his guilty plea, Smith's sentencing was set for July 29, 2026. The conspiracy charge carries a maximum prison sentence of five years.
Michael Smith pleaded guilty in federal court in the Southern District of New York to conspiracy to commit wire fraud for manipulating music streaming platforms with AI-generated songs and bot-driven streams. Prosecutors said the scheme generated more than $8 million in fraudulent royalties, and Smith agreed to forfeit $8,091,843.64.
Prosecutors said Michael Smith operated a music streaming fraud scheme from 2017 through 2024, using AI-generated songs, thousands of bot accounts, automated playback, and cloud infrastructure to inflate streams and divert royalty payments from legitimate artists and rights holders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.