
Streaming, and Spotify for that matter, couldn't have been made possible without the accessibility and connectivity of the Internet. Unfortunately, with that openness and interconnectedness, came malicious attackers who look to exploit weaknesses in web sites and applications.
At Spotify, we're committed to protecting our information, as well as yours. So two years ago we began using the HackerOne platform for our bug bounty program. Now, we're looking back on successes and learnings that will continue to help improve the program at Spotify.
Want to learn more? We've broken it down into six frequently asked questions.
1. First off, what is a bug bounty program? There are ethical and responsible security researchers who discover weaknesses via the same tactics and tools used by hackers. They report these weaknesses to site owners, so that they can be fixed before others can use them for malicious purposes. Bug bounty programs exist to make it easier for security researchers to report these weaknesses to site owners. As a token of gratitude, the site owners often reward money or swag to the researchers for their efforts.
2. When and why did Spotify start a bug bounty program? Our Security team launched its bug bounty program in 2015, when we were a very small team that occasionally received vulnerability reports from researchers responsibly disclosing bugs. Although we didn't receive a huge number of reports, it was clear that managing them by hand, primarily through email, would prove difficult. During that time, we had been rewarding reports with any swag we happened to have on hand, or giving them credit on our wall of fame at https://www.spotify.com/bounty/. However, because this work and reporting was so crucial, we wanted to start giving cash for bug submissions.
In May 2017, we moved our bug bounty program onto HackerOne, a leading cybersecurity bug bounty platform, to take advantage of their platform and managed services. We now accept bug bounty reports at https://hackerone.com/spotify. From there, the HackerOne team reviews the report for validity and severity, then loops in our Spotify Security team. Then, we're able to work together to find a resolution and reward the security researcher who found the bug in the first place.
3. What are some of the benefits of using HackerOne? Since we started using the HackerOne platform and managed services, we've received over 365 valid and actionable reports and rewarded over $120,000 to security researchers for their efforts.
4. What sort of problems have been reported? We receive the largest amount of reports on our most visible websites, www.spotify.com and community.spotify.com, but also receive reports on our mobile applications, desktop applications, and other apps and software.
One other area where we face challenges is with partner development. The reports we get here are for sites that Spotify has contracted to have built, or companies that Spotify has acquired that didn't have the benefit of being developed with the same security protocols in place.
5. Why is finding these vulnerabilities such a big deal? If the vulnerabilities mentioned above were to be discovered by a malicious actor, our websites or apps could be attacked, thus harming the brand and reputation of Spotify. Or, the credentials could be used for lateral movement or in a phishing attack. None of this is good for us or our users.
6. So what's the next step for security at Spotify? As mentioned, a lot of reports come regarding sites developed by our partner developers. So to help them, we're developing something we call the Global Preferred Production Partner Program. It's a security-focused set of standards and runtime environments for Partner Developers outside of Spotify. It also includes a set of expectations for vendors that help us ensure we can rapidly and effectively respond and correct vulnerabilities that are reported to us through the bug bounty program.
So far, working with HackerOne has raised security awareness within our engineering organization, exposed weaknesses in our security posture, and helped us better understand our attack surface. Even if you have no experience in bug hunting, check out our program page at https://hackerone.com/spotify. We think there are always opportunities to make our security stronger.
Europe Stories
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
16/01/2026
The start of a new year brings fresh possibilities. Whether you're diving in with big goals or simply setting new intentions, audiobooks can bring inspirati...
16/01/2026
In 2025 we launched the Spotify Partner Program to give creators more ways to tu...
15/01/2026
The SGL Carbon site in Bonn has a long tradition of training. For many years, young talent has been successfully trained here, regularly achieving excellent exa...
15/01/2026
The JEC Composites Innovation Awards annually honor the most innovative and ambi...
15/01/2026
X-energy Reactor Company, LLC ( X-energy ) and SGL Carbon LLC ( SGL ) have signed a 10-year framework agreement to provide graphite for the deployment of X-ener...
15/01/2026
RT is tonight announcing that Mari Hurley has decided to leave her role as RT 's Chief Financial Officer to take up a new position outside RT . Mari will r...
15/01/2026
15 Jan 2026
VEON's Kyivstar Reaches 3.0 million Customers with Starlink Dir...
15/01/2026
Views to free streaming service U grew by 15%, average monthly active users by 23% and registrations by 18%
UKTV's channels achieved record viewing share, ...
15/01/2026
Thursday 15 January 2026
Sky Sports to show Final Stage of inaugural FIFA Women's Champions Cup
Sky and FIFA have agreed an exclusive new partnership whi...
15/01/2026
Thursday 15 January 2026
The official trailer for the second season of Seth Mac...
15/01/2026
Wuppertal January 15, 2026
Riedel RefCam Takes Center Court in German Basketba...
15/01/2026
Arvato Systems Named Launch Partner for AWS European Sovereign Cloud
As a launch partner for the AWS European Sovereign Cloud, Arvato Systems enables customer...
14/01/2026
Staines-upon-Thames, UK, 13th January, 2026 ITV, one of the UKs leading broadcasters, has selected Yospace, the global leader in Dynamic Ad Insertion (DAI), to ...
14/01/2026
Steiger Media's adoption of Calrec's compact Argo M console not only makes its innovative new hybrid truck faster, more efficient, and agile, but also e...
14/01/2026
Press Release: The Boston Globe Names Cartesian a Top Place to Work in 2025
January 14, 2026
News
Cartesian - January 14, 2026 - EINPresswire.com - Sp...
14/01/2026
Comscore and Marcus Theatres Announce Five-Year Extension for Cinema ACE and Ent...
14/01/2026
Comscore and Santikos Entertainment Announce Five-Year Circuit Wide Commitment t...
14/01/2026
Wednesday 14 January 2026
Sky News announces Cathy Newman to lead flagship new political programme
Sky News today announces that award-winning journalist and ...
14/01/2026
The first stamp of An Post's 2026 Stamp Programme, marking 100 Years of Broadcasting, was unveiled at the GPO by Patrick O'Donovan TD, Minister for Cult...
14/01/2026
It's official! Beverley Callard has landed in Carrigstown. The beloved actor, known for her unforgettable roles and iconic screen presence, is joining the c...
13/01/2026
Independent media in Brazil and Colombia is facing an urgent crisis of traditional business models alongside a deteriorating security environment, according to ...
13/01/2026
Luxembourg, December 17, 2025 - SES S.A. ( SES or the Company ), a leading spa...
13/01/2026
Written and executive produced by Steve Lightfoot and Angela LaManna, produced b...
13/01/2026
New updates to Hitmaker Expansion from Celemony and Softube Edit pitch-perfect vocals with Melodyne Essential and get radio-ready guitar tones from Softube...
13/01/2026
Live broadcasts from RT 2FM Breakfast with Carl, Roz & Aisling, RT Radio 1 Tod...
12/01/2026
Spotify's new co-CEOs, Alex Norstr m and Gustav S derstr m, start off the new year with a message of renewed leadership, creative responsibility, and what...
12/01/2026
At Spotify, we listen to a lot of music. And every year, our global editors and artist partnerships teams come together to spotlight the emerging voices we beli...
12/01/2026
Spotify's global editors and Songwriter & Publisher Partnerships team spend their days immersed in new music, tracking the writers behind the songs breaking...
12/01/2026
Rohde & Schwarz opens larger office in Japan and increases its support for the J...
12/01/2026
X-Rite and Rhopoint Launch Rhopoint PANTORA Aesthetix to Streamline Creation of...
12/01/2026
12 Jan 2026
VEON's Kyivstar Launches 5G Pilot in Lviv Lviv, January 12, 2026 - VEON, a global digital operator (Nasdaq: VEON), today announces that Kyivsta...
12/01/2026
Monday 12 January 2026
The ultimate betrayal: Harry and Jamie Redknapp, Paul Me...
12/01/2026
Rohde & Schwarz opens larger office in Japan to increase its support for the Jap...
12/01/2026
Welcome to the AVECO team: introducing new members of management
At AVECO, we are continuing to implement our #newAVECO strategy, which aims to build an even s...
12/01/2026
For the first time in the nine-year history of Dancing with the Stars, the first...
10/01/2026
This year, podcasts are making their Golden Globes debut with a new category honoring the medium's leading shows and creators. To mark the occasion, Spotify...
09/01/2026
RT Player has 157 million streams, up 10% year-on-year
An increase on 2024, RT...
09/01/2026
RT 2FM has today announced the highly anticipated list of 2FM Rising Artists for 2026, kicking off 2FM Rising week for the eighth year on The Tracy Clifford Sh...
09/01/2026
RT to Host the 2026 RTS Ireland Awards
Thursday, 16 April 2026 | Dublin Royal Convention Centre
The RTS Ireland Television Awards 2026 | Gradaim RTS 2026 | R...
08/01/2026
An evidence-based analysis on disinformation and information manipulation in Sudan's ongoing conflict is published today. (January 8th 2026).
Thomson Found...
08/01/2026
In 2025 we launched the Spotify Partner Program to give creators more ways to tu...
08/01/2026
On Wednesday in Los Angeles, Spotify welcomed creators and press to a brunch cel...
08/01/2026
TSA awards Rohde & Schwarz contract for advanced airport screening ahead of Socc...
08/01/2026
The review looks back at DPA's miniature microphone development over the years. It compares the evolving technologies from the original mics through CORE an...
08/01/2026
Comscore Launches Audio Targeting and Measurement Capabilities with The Trade De...
08/01/2026
Tonight, on RT Prime Time at 9:35pm on RT One and RT Player
Tonight, Prime T...