Back to The Local Vocal
The Local VocalMedium
PhishingSpotify
Email
Medium risk PhishingEncountered ViaEMAIL 4 August 2026
RegionOtago

Your Spotify subscription is on hold!

A coordinated campaign impersonating Spotify is targeting New Zealand organisations via high-reputation marketing infrastructure.

A sophisticated phishing campaign has been detected impersonating Spotify, specifically utilizing 'Account on Hold' and 'Payment Unsuccessful' lures. The messages originate from the infrastructure of a global marketing platform (hubspotfree.eu1.hs-send.com), which allows the campaign to bypass many traditional reputation-based security filters. Technical analysis indicates that while the sender domain passes DKIM and DMARC checks, it failed SPF authentication, highlighting a deliberate attempt to leverage high-reputation delivery nodes for malicious purposes.

The clinical indicator of fraud in this campaign is the 'Reply-To' mismatch. Although the message appears to be from a legitimate service domain, all technical replies are directed to an unrelated domain (mail.pipefy.com). This 'Reply-Chain Hijack' technique is designed to divert user interactions toward attacker-controlled communication channels, bypassing official organisational oversight.

The email body employs high-fidelity Spotify branding, including accurate color palettes and logo placement, to create a sense of financial urgency. Users are prompted to 'Update Payment Information' via links that lead to credential harvesting portals. This campaign is particularly effective because it targets the common business workflow of managing SaaS subscriptions, relying on the high volume of legitimate marketing mail typically received by organisations to remain undetected.

Organisations are advised to treat any unsolicited subscription alerts with clinical skepticism. Legitimate billing and account status updates for Spotify should be verified strictly through the official spotify.com portal or the mobile application. Enforcing strict 'First Contact' safety tips and encouraging users to utilize the 'Report Phishing' mechanism remain the most effective methods for refining tenant-level security against these high-reputation infrastructure abuses.

Email authorisation
SPF
fail
DKIM
pass
DMARC
pass
COMPAUTH
pass
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainhubspotfree.eu1.hs-send.com
Replies to this message would not go back to the sender. They would be routed to mail.pipefy.com.
Reply-To Domain Intelligence

Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.

Reply-To domainmail.pipefy.com
Email Sample
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Verify account status strictly via official mobile applications or the official spotify.com portal.
  • Monitor for 'Reply-To' mismatches in organisational mail flow to identify identity-based probes.
  • Implement 'Safe Links' policies to intercept and rewrite URLs from high-volume marketing nodes.
  • Educate staff on the risks of interacting with unsolicited subscription renewal alerts.
Spotify logo
Is it real?
Got an email from Spotify?

See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing