Updated:
July 2, 2026
Spotify Data Leak Panic: 256M Tracks Exposed (Updated July – 2026)
What Happened
In late December 2025, Spotify confirmed it was investigating unauthorized scraping of its music library after Anna’s Archive claimed it had backed up a large portion of Spotify’s catalog. The group first released metadata for 256 million tracks and said it had archived 86 million audio files.
The incident moved beyond metadata in February 2026. Anna’s Archive released more than 2.8 million audio files across 47 BitTorrent torrents, totaling about 6.4TB, while a court order already prohibited distribution of the scraped recordings.
Spotify described the activity as unlawful scraping and said the third party used illicit tactics to bypass digital rights management controls to access some audio files. The company said it disabled the user accounts involved, implemented additional safeguards, and continued monitoring for suspicious behavior.
The legal status changed in January 2026. Spotify, Universal Music Group, Sony Music Entertainment, and Warner Music Group filed suit against Anna’s Archive, and the case was unsealed on January 16, 2026. The complaint accused the group of “brazen theft” of nearly all commercial sound recordings and asserted copyright infringement, breach of contract, CFAA, and DMCA claims.
The outcome arrived on April 14, 2026. Judge Jed S. Rakoff of the Southern District of New York entered a $322 million default judgment after the anonymous operators never appeared. Roughly $300 million went to Spotify on the DMCA anti-circumvention claim, calculated at $2,500 for each of 120,000 files, and about $22.2 million went to the labels for statutory copyright damages.
The judgment is likely difficult to collect, since the operators remain anonymous. A permanent injunction ordered domains and service providers to disable access to Anna’s Archive domains, but the site has historically relaunched on new domains.
The AI training angle is no longer only theoretical. The ruling created a per-file DMCA damages template that treats authenticated scraping and access control circumvention as high legal risk, with direct implications for AI training datasets built from gated or protected content.

Timeline: From First Access To Latest Update
- Dec. 20, 2025 (Public Claim And Initial Metadata Release)
Anna’s Archive published a blog post claiming it discovered a method to scrape Spotify at scale. The group said it released metadata for 256 million tracks, archived 86 million audio files, and planned bulk torrent distribution.
- Dec. 22, 2025 (Spotify Confirms Investigation Publicly)
Major outlets reported that Spotify confirmed unauthorized access and active monitoring. Spotify said a third party scraped public metadata and used illicit tactics to circumvent DRM to access some audio files.
- Dec. 22 To Dec. 23, 2025 (Spotify Containment Steps Reported)
Spotify said it identified and disabled user accounts engaged in unlawful scraping. The company said it implemented new safeguards for anti copyright attacks and kept monitoring suspicious behavior.
- January 2, 2026 (Civil Lawsuit And Emergency Order)
Spotify and the record company plaintiffs filed the civil action in the Southern District of New York and obtained an emergency temporary restraining order. The complaint asserted copyright infringement, breach of contract, CFAA, and DMCA claims.
- January 16 To January 20, 2026 (Unsealing And Preliminary Injunction)
The complaint became public on January 16, 2026. Judge Jed S. Rakoff entered a preliminary injunction on January 20, 2026, and the order prohibited Anna’s Archive from hosting, linking to, distributing, or enabling downloads of the scraped recordings.
- February 2026 (Actual Audio Torrents Appear)
Anna’s Archive released more than 2.8 million audio files through 47 BitTorrent torrents, totaling about 6.4TB. The release defied the court order already in place and changed the incident from a metadata release into partial audio distribution.
- March 25, 2026 (Default Judgment Request)
The plaintiffs moved for default judgment after Anna’s Archive failed to answer, respond, or appear. The motion sought direct copyright infringement, breach of contract, and DMCA relief, while the CFAA claim was later dismissed without prejudice.
- April 14, 2026 (Default Judgment And Permanent Injunction)
Judge Rakoff entered a $322 million default judgment and permanent injunction. The award included $300 million for Spotify under the DMCA anti-circumvention claim and about $22.2 million for the labels on statutory copyright damages.
What Data Or Systems Were Affected
Reporting and Spotify’s statements indicate the incident involved three broad categories:
- Public Metadata For Track Catalogs
Anna’s Archive claimed it released metadata for roughly 256 million tracks, including artist name, track title, album details, ISRC identifiers, and related catalog attributes. - Archived Audio Files For A Portion Of Spotify Listening Activity
The group claimed it archived roughly 86 million audio files. Court filings repeated Anna’s Archive’s claim that the files represented 99.6 percent of listens on Spotify and about 37 percent of songs available on the platform. - Released Audio Files In February 2026
The public release expanded in February 2026, when more than 2.8 million audio files appeared across 47 BitTorrent torrents. The released batch was reported at roughly 6TB to about 6.4TB of audio data.
Spotify stated the incident did not involve non public user information. It said the only user related data was tied to public playlists, which are visible to other users. This separates the case from a conventional data breach, where attackers target private customer records rather than licensed content.
Who Was Responsible (Confirmed Vs Alleged)
Confirmed
Spotify attributed the scraping to a third party that used unlawful methods and said it disabled accounts used in the activity. Spotify did not publicly identify individuals or organizations behind the accounts.
Claimed
Anna’s Archive publicly claimed responsibility, describing itself as an open source search engine for shadow libraries and stating the scrape was part of an effort to build a preservation archive for music.
No law enforcement agency has publicly announced arrests or formal attribution as of the latest confirmed reporting.
How The Attack Worked
Spotify has not published full technical details of the scraping method. Court filings and reporting describe a likely pattern consistent with large scale authenticated extraction:
- Use of thousands of accounts, automated tooling, and repeated requests to pull large volumes of content and metadata
- Abuse of platform access intended for user playback rather than bulk extraction
- Attempts to evade rate limits, account controls, and behavioral detection mechanisms
- Circumvention of Spotify technological protection measures to obtain audio files outside official playback workflows
- Bulk distribution through BitTorrent after the initial metadata release
These techniques mirror the controls covered in data exfiltration prevention guidance, where access limits, monitoring, and behavioral detection reduce the volume an attacker can remove. Spotify said it disabled the accounts involved and added safeguards designed to reduce similar activity in the future.
Company Response And Customer Remediation
Spotify characterized the incident primarily as a piracy and content protection issue rather than a compromise of user databases. The company said it:
- Identified and disabled user accounts tied to scraping
- Implemented new safeguards for similar anti copyright activity
- Continued monitoring for suspicious behavior
- Worked with industry partners to defend creators’ rights
- Filed civil action with Universal Music Group, Sony Music Entertainment, and Warner Music Group
- Obtained an injunction, domain related relief, and a $322 million default judgment
Spotify said there was no indication that private user data was compromised.
The company did not announce user compensation or credit monitoring programs, since reporting did not indicate exposure of payment information, passwords, or private subscriber records.
Government, Law Enforcement, And Regulator Actions
No public regulator statement indicated a consumer data breach investigation tied to the Spotify scraping claims through April 2026. The publicly documented action centered on copyright, platform abuse controls, and DRM circumvention rather than exposure of personal user records.
Federal court action moved quickly. The Southern District of New York issued a temporary restraining order in January 2026, followed by a preliminary injunction and the April 2026 default judgment.
The permanent injunction ordered Anna’s Archive to destroy scraped works and ordered domain registries, registrars, hosting providers, and internet service providers to disable access to listed Anna’s Archive domains. Enforcement remains difficult, since the operators remain unidentified and some infrastructure may sit outside easy U.S. reach.
Financial, Legal, And Business Impact
The incident now has a defined civil outcome, even though collection remains uncertain:
- Copyright Enforcement And Rights Holder Pressure
Spotify, Universal Music Group, Sony Music Entertainment, and Warner Music Group sued Anna’s Archive in a case reported as a $13 trillion damages claim. The complaint accused the operators of “brazen theft” of millions of files containing nearly all commercial sound recordings. - Default Judgment
On April 14, 2026, the court entered a $322 million default judgment. Spotify received $300 million under the DMCA anti-circumvention claim, calculated at $2,500 for each of 120,000 files, and the labels received about $22.2 million for statutory copyright damages across 148 works. - Enforcement Limits
The monetary award may be difficult to collect, since Anna’s Archive operators remain anonymous. The permanent injunction targets domains, hosting, and service providers, but Anna’s Archive has previously shifted domains after takedown pressure. - Piracy And Revenue Impact
The February release made actual audio files publicly available rather than only metadata. That shift increased the risk of unauthorized redistribution outside paid streaming and licensing channels. - AI Training And Dataset Risk
The ruling created a per-file DMCA damages template for authenticated scraping that circumvents access controls. AI teams using scraped datasets from gated platforms face greater legal risk when access controls or technical protections are bypassed. - Platform Trust And Security Optics
Large scale scraping can damage platform trust even without a user data breach. The incident shows how account abuse, automation, and content protection failures can become legal and business risks at catalog scale.
What Remains Unclear
The core civil liability question is no longer unresolved after the April 14, 2026 default judgment. Several operational and enforcement details remain unclear:
- The exact technical method used to scrape at scale
- Whether all claimed audio files were captured directly from Spotify’s streaming pipeline or through another workflow
- How long the scraping activity occurred before discovery
- How widely the February 2026 audio torrents were mirrored or retained after removal from Anna’s Archive listings
- Whether Spotify or the labels will collect any meaningful portion of the $322 million judgment
- Whether Anna’s Archive will keep relaunching on new domains after the permanent injunction
- Whether law enforcement or prosecutors will bring separate criminal action
- Whether Spotify will publish more details on safeguards or detection mechanisms
- Whether any user accounts were compromised versus created and operated solely for scraping
Spotify has not confirmed the full scope of audio file access and has not said how many audio files were actually taken.
Why This Incident Matters
This case matters because it shows how large scale scraping and account abuse can shift from isolated piracy into industrial scale content replication. Spotify is one of the world’s largest music distributors, and the claim that a third party can extract a dataset measured in hundreds of terabytes underscores how difficult it can be to prevent determined actors from turning a streaming platform into a content source for redistribution.
It also highlights the growing overlap between piracy, security, and AI. A dataset containing modern music at scale could be used not just for illegal redistribution, but also for training generative AI systems, raising major questions about licensing, model ethics, and enforcement. Even when user data is not involved, the ability to defeat content protection at scale is a major risk for any platform dependent on copyrighted distribution, and it moves content protection squarely into the scope of cybersecurity compliance.
Read More Breach Reports Here!
FAQ
Public reporting described unlawful scraping tied to a group called Anna’s Archive, with Spotify confirming unauthorized access involving public metadata and some audio files.
The 256 million figure refers to rows of track metadata, and TechCrunch reported the group claimed metadata coverage for an estimated 99.9% of Spotify’s catalog.
No, Spotify told Recorded Future News that it did not consider the incident a “hack” and described it as stream-ripping and scraping that used third-party user accounts rather than access to Spotify business systems.
Reporting described two main components: a large metadata database (artist, album, titles, and related fields) and a bulk archive described as about 86 million music files, with Spotify saying a third party used illicit tactics to get access to some audio files.
Spotify said it identified and disabled the user accounts involved and put additional safeguards in place while monitoring for suspicious behavior.
No clear public reporting tied this incident to stolen listener login data, and Spotify framed the event as unlawful scraping via user accounts rather than a compromise of user records.
Yes, treat it as high-risk and avoid clicking links in unsolicited messages, then check your account only in the Spotify app or by typing the official site address yourself.
Spotify says it will not ask for personal information over email such as your password or payment info and it will not ask you to download anything from its emails, so messages asking for those items should be treated as scams.
Yes, Spotify disclosed a 2020 incident where a vulnerability exposed some users’ Spotify account registration information to certain business partners and Spotify reset affected passwords.
It means the password you used has shown up in known breached credential data, so it is higher risk if reused on any account and should be replaced with a unique password.
Jay Z’s catalog was largely removed from Spotify in 2017 at the artist’s request while his music remained on TIDAL, and reporting tied the move to streaming availability strategy around TIDAL and competing services.
About 0.04 GB per hour at Normal quality (about 96 kbit/s), about 0.07 GB per hour at High (about 160 kbit/s), and about 0.14 GB per hour at Very High (about 320 kbit/s), with exact usage varying by settings and network conditions.
Sources
- Euronews Next — Spotify investigates data breach after pirate group claims it scraped its music library (Dec. 22, 2025)
https://www.euronews.com/next/2025/12/22/spotify-investigates-data-breach-after-pirate-group-claims-it-scraped-its-music-library - The Guardian — Activist group says it has scraped 86m music files from Spotify (Dec. 22, 2025)
https://www.theguardian.com/technology/2025/dec/22/spotify-music-scraped-annas-archive - Billboard — Spotify Music Library Scraped by Pirate Activist Group (Dec. 22, 2025)
https://www.billboard.com/pro/spotify-music-library-scraped-pirate-activist-group/ - The Record — Spotify disables accounts after open source group scrapes 86 million songs (Dec. 2025)
https://therecord.media/spotify-disables-accounts-after-open-source-group-scrapes-86-million-songs - TechCrunch — Pirate group Anna’s Archive says it scraped 86 million songs from Spotify (Dec. 23, 2025)
https://techcrunch.com/2025/12/23/pirate-group-annas-archive-says-it-has-scraped-86-million-songs-from-spotify/ - Malwarebytes — Hacktivists claim near total Spotify music scrape (Dec. 23, 2025)
https://www.malwarebytes.com/blog/news/2025/12/hacktivists-claim-near-total-spotify-music-scrape - Engadget — Pirate group Anna’s Archive says it has scraped Spotify in its entirety (Dec. 23, 2025)
https://www.engadget.com/entertainment/streaming/pirate-group-annas-archive-says-it-has-scraped-spotify-in-its-entirety-211914755.html - Android Central — Anna’s Archive backed up 300TB of Spotify songs and metadata (Dec. 2025)
https://www.androidcentral.com/apps-software/spotify/annas-archive-backed-up-300tb-spotify - Yahoo News / Decrypt — Shadow ‘Archive’ says it copied virtually all of Spotify’s music (Dec. 22, 2025)
https://www.yahoo.com/news/articles/shadow-archive-says-copied-virtually-170622522.html
Get In Touch


