Skip to main content
My Consumer Finance

Fake Spotify support and account-hold phishing scams

Fake Spotify support and account-hold phishing: cloned help desks, MFA theft, gift-card unlock fees, and how to recover through official channels.

An email, SMS, or in-app-looking notice says your Spotify account is on hold, Premium was charged fraudulently, or “unusual login from another country” requires you to call or chat a “Spotify Support” number. The agent asks for your password, MFA code, or payment in Apple, Google Play, or Steam gift cards to “release the hold.” A cousin script hijacks the account first, then the thief’s fake help desk sells you a recovery.

Distinct from family-plan invite phishing in Fake Spotify family plan scams, but it uses the same password and gift-card playbook as Phishing and account takeover and Gift cards and prepaid debit risks. Broader consumer fraud patterns: Credit and debt scams.

Two support scripts to expect

ScriptHookGoal
Account-hold / billing alert“Your Premium will cancel in 2 hours—verify now”Steal login + MFA; drain linked cards or sell the account
Post-takeover “recovery desk”WhatsApp / Telegram “Spotify Security” after you lose accessCash-out with gift cards or crypto “unlock fees”
Refund bait“We overcharged you $79.99—confirm routing to reverse it”Remote-access malware or bank details (Apple Support iMessage cousins)

Spotify’s real help flows live in the official Spotify app Help or the support pages Spotify publishes—not a random callback number in a text, and not a stranger who needs gift cards.

Red flags

  • Support that messages you first on WhatsApp, Telegram, Discord, or SMS with a phone number to call.
  • Anyone asking for your password, MFA code, session cookie, or backup codes.
  • Payment demands in gift cards, Zelle, crypto, or prepaid debit to “clear a billing hold.”
  • URLs that are not Spotify’s official domain (extra hyphens, look-alike TLDs).
  • Urgency: “account deleted tonight” or “fraud department waiting on the line.”
  • Remote-access apps (AnyDesk, TeamViewer) “so we can fix Premium.”

Worked example: the “billing hold” SMS

Jordan gets a text: “Spotify: Unusual $49.99 charge. Hold placed. Call 1-800-XXX-XXXX now.” The voice on the line says Premium Support and asks Jordan to read the SMS code that just arrived, then to buy $200 in Apple gift cards and read the numbers “to reverse the charge.” Jordan buys cards at a Target self-checkout. The line goes dead. Spotify’s real account page still shows the usual $11.99 Premium; the Apple cards are drained.

Jordan’s next steps: stop buying cards; from a trusted browser open Spotify’s official password reset / session revoke; change the email password if reused; enable app-based MFA; tell the card issuer about the gift-card spend (recovery is often limited); report to FTC ReportFraud and Spotify; ignore any “supervisor” callback that asks for more cards. Same irreversible-payment pattern as Zelle and P2P scams.

What real Spotify help looks like

  1. Open the Spotify app or type Spotify’s official site yourself—do not tap SMS links.
  2. Use in-app Help / account recovery; Spotify does not need gift-card PINs to fix billing.
  3. Check billing through Apple App Store, Google Play, or your card issuer if Premium is billed by a store—not a stranger on Telegram.
  4. Revoke sessions and change passwords after any suspected phish.

Named brands that appear in these scripts include Spotify, Apple App Store, Google Play, Steam, Target, Walmart, Best Buy (gift-card aisles), WhatsApp, Telegram, and common remote-access tools. None of those gift-card aisles are a legitimate Spotify fee channel.

If you already shared codes or paid

  1. Reset Spotify password and revoke sessions immediately; change reused passwords elsewhere.
  2. Call your bank or card issuer about unauthorized Premium charges and gift-card purchases.
  3. Preserve texts, call logs, and gift-card receipts for reports.
  4. File ReportFraud.ftc.gov; report the account takeover to Spotify through official Help.
  5. Do not pay a second “escalation” or “cybercrime unit” fee.

Checklist

  1. Treat unsolicited Spotify “hold” calls and texts as hostile until proven otherwise.
  2. Never give MFA codes or passwords to someone who contacted you.
  3. Never pay support with gift cards, crypto, or Friends & Family P2P.
  4. Recover only through the official app or typed URL.
  5. Revoke sessions after any scare.
  6. Teach teens and roommates who share Premium the same rules.

Fake Uber account-hold / Trust & Safety cousins (same MFA + gift-card playbook): Fake Uber account-hold scams.

Educational only. Not legal, banking, or fraud-recovery advice. Scam tactics change; verify support only through official Spotify channels.