
Streaming, and Spotify for that matter, couldn't have been made possible without the accessibility and connectivity of the Internet. Unfortunately, with that openness and interconnectedness, came malicious attackers who look to exploit weaknesses in web sites and applications.
At Spotify, we're committed to protecting our information, as well as yours. So two years ago we began using the HackerOne platform for our bug bounty program. Now, we're looking back on successes and learnings that will continue to help improve the program at Spotify.
Want to learn more? We've broken it down into six frequently asked questions.
1. First off, what is a bug bounty program? There are ethical and responsible security researchers who discover weaknesses via the same tactics and tools used by hackers. They report these weaknesses to site owners, so that they can be fixed before others can use them for malicious purposes. Bug bounty programs exist to make it easier for security researchers to report these weaknesses to site owners. As a token of gratitude, the site owners often reward money or swag to the researchers for their efforts.
2. When and why did Spotify start a bug bounty program? Our Security team launched its bug bounty program in 2015, when we were a very small team that occasionally received vulnerability reports from researchers responsibly disclosing bugs. Although we didn't receive a huge number of reports, it was clear that managing them by hand, primarily through email, would prove difficult. During that time, we had been rewarding reports with any swag we happened to have on hand, or giving them credit on our wall of fame at https://www.spotify.com/bounty/. However, because this work and reporting was so crucial, we wanted to start giving cash for bug submissions.
In May 2017, we moved our bug bounty program onto HackerOne, a leading cybersecurity bug bounty platform, to take advantage of their platform and managed services. We now accept bug bounty reports at https://hackerone.com/spotify. From there, the HackerOne team reviews the report for validity and severity, then loops in our Spotify Security team. Then, we're able to work together to find a resolution and reward the security researcher who found the bug in the first place.
3. What are some of the benefits of using HackerOne? Since we started using the HackerOne platform and managed services, we've received over 365 valid and actionable reports and rewarded over $120,000 to security researchers for their efforts.
4. What sort of problems have been reported? We receive the largest amount of reports on our most visible websites, www.spotify.com and community.spotify.com, but also receive reports on our mobile applications, desktop applications, and other apps and software.
One other area where we face challenges is with partner development. The reports we get here are for sites that Spotify has contracted to have built, or companies that Spotify has acquired that didn't have the benefit of being developed with the same security protocols in place.
5. Why is finding these vulnerabilities such a big deal? If the vulnerabilities mentioned above were to be discovered by a malicious actor, our websites or apps could be attacked, thus harming the brand and reputation of Spotify. Or, the credentials could be used for lateral movement or in a phishing attack. None of this is good for us or our users.
6. So what's the next step for security at Spotify? As mentioned, a lot of reports come regarding sites developed by our partner developers. So to help them, we're developing something we call the Global Preferred Production Partner Program. It's a security-focused set of standards and runtime environments for Partner Developers outside of Spotify. It also includes a set of expectations for vendors that help us ensure we can rapidly and effectively respond and correct vulnerabilities that are reported to us through the bug bounty program.
So far, working with HackerOne has raised security awareness within our engineering organization, exposed weaknesses in our security posture, and helped us better understand our attack surface. Even if you have no experience in bug hunting, check out our program page at https://hackerone.com/spotify. We think there are always opportunities to make our security stronger.
Europe Stories
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
28/05/2026
Hellenic Civil Aviation Authority modernizes nationwide ATC voice communications...
28/05/2026
Wuppertal May 28, 2026
Berliner Ensemble Upgrades Backstage Infrastructure With Riedel Stage SystemsRiedel Communications today announced that Berliner Ensemb...
28/05/2026
Harmonic's Software-Based XOS Advanced Media Processor Powers Cost-Efficient 24/7 Channel Origination and Direct-to-Consumer Delivery
SAN JOSE, Calif. - M...
28/05/2026
RT presents Wild Conamara, a two-part natural history documentary that brings a...
27/05/2026
Spotify already brings together listeners' favorite music, podcasts, and audiobooks in one place. Now, we're trialing a new format that expands the cont...
27/05/2026
The best podcast moments deserve more than just a mental note. That's why today, we're making those moments easier to save and share with clips.
Whethe...
27/05/2026
On Purpose is one of the most popular podcasts in the world, known for conversat...
27/05/2026
On May 8, 1,500 of Olivia Rodrigo's top fans gathered in Barcelona's Tea...
27/05/2026
Hybrid design combines large-diaphragm capsule & ribbon
JZ Microphones have teamed up with Grammy-winning producer and engineer Marc Urselli to develop a ne...
27/05/2026
Three new plug-ins inspired by classic tape effects
AIR Music Tech's latest release delivers a set of plug-ins that aim to capture the character, moveme...
27/05/2026
Piano played on the edge of silence
The Crow Hill Company's Vaults collection offers a continual rotation of instruments that are given away for free fo...
27/05/2026
Recreates Moog's iconic Memorymoog polysynth
Arturia's vast software instrument range offers a combination of new and old, with innovative modern so...
27/05/2026
Offers loudness levelling for speech and dialogue
Accentize have built up a solid reputation with their audio-restoration tools, and their latest plug-in is...
27/05/2026
10,000 units strong - The Rohde & Schwarz R&S M3SR Radio 4400 Rohde & Schwarz celebrates a major manufacturing milestone, producing its 10,000th R&S M3SR Radi...
27/05/2026
27 May 2026
VEON's Kyivstar and Uklon Launch Ukraine's First Live Testi...
26/05/2026
26 May 2026
New Research Shows Mobile Tax Reform Could Accelerate Economic Gain...
26/05/2026
26 May 2026
VEON's Kyivstar Expands Renewable Energy Portfolio with Acquisi...
26/05/2026
Tuesday 26 May 2026
Millie Bright, Michelle Agyemang, and Gemma Bonner join Sky...
26/05/2026
Tuesday 26 May 2026
Sky confirms new Boyzone documentary One For The Road will ...
26/05/2026
Customers can roam with ease, with nothing to install, download, or set-up Tuesday 26 May 2026
Sky Mobile boosts roaming to 120 destinations for just £2 a day
...
26/05/2026
Roku Expands Premium Subscriptions Experience with FOX One Roku customers in the U.S. can now subscribe to FOX One on The Roku Channel to stream FOX's ful...
25/05/2026
The RT Concert Orchestra will celebrate the centenary of Hollywood icon Marilyn...
24/05/2026
Win Bob Moog Tribute Edition Minimoog Model D #001
The Bob Moog Foundation are currently running a fundraising raffle for a brand-new Bob Moog Tribute Editi...
23/05/2026
AI-powered vocal tool gains first new language expansion
IK Multimedia's AI-powered voice-creation software has seen a number of updates since it launch...
22/05/2026
At our 2026 Investor Day, we shared an inside look at the rebuild of our advertising business. This pivot to our own purpose-built platform is already driving s...
22/05/2026
Podcasting on Spotify continues to grow, and so do the ways listeners engage with it. At Investor Day 2026, we shared how we're building the next chapter of...
22/05/2026
Limited-time collections now available
Restoration experts CEDAR Audio have recently launched a new line of Icons plug-ins that make their powerful processo...
22/05/2026
Three new classics join Model Pass line-up
Boss' PX-1 Plugout Pedal offers an innovative approach to guitar pedals, providing users with a hardware stom...
22/05/2026
At its Meitingen site, SGL Carbon has implemented two key projects to further de...
22/05/2026
Catch the latest in Irish music live from venues such as Whelan's, R is n Du...
21/05/2026
Spotify has always been about helping you find something you want to listen to. And over the years, we've learned your taste and the moments that matter to ...
21/05/2026
Getting concert tickets today can feel like a race you're set up to lose.
You show up at the right time, refresh endlessly, and still miss out. Too often, ...
21/05/2026
In 2022, Spotify entered a new chapter by introducing audiobooks to our platform. Since then, we've grown our catalog to include more than 700,000 titles, e...
21/05/2026
Opening remarks
ALEX
Good morning everyone, I'm Alex [Norstr m].
GUSTAV
And I'm Gustav [S derstr m].
ALEX
Whether you've been following our j...
21/05/2026
Today, Spotify hosted our third Investor Day in New York City, offering the fina...
21/05/2026
Spotify hat heute seinen dritten Investor Day in New York City veranstaltet und der Finanzwelt tiefere Einblicke in das Gesch ft, die Produktstrategie und die l...
21/05/2026
Aujourd'hui, Spotify a organis son troisi me Investor Day New York. En pl...
21/05/2026
Oggi, a New York City, Spotify ha presentato il suo terzo Investor Day, offrendo...
21/05/2026
Hoy Spotify celebr su tercer Investor Day en Nueva York, donde ofrecimos a la c...
21/05/2026
Hari ini, Spotify menyelenggarakan Investor Day yang ketiga di New York City, me...
21/05/2026
2026 : (Investor Day) , , . ...
21/05/2026
Hoje, o Spotify realizou seu terceiro Investor Day em Nova York, oferecendo co...
21/05/2026
Spotify Investor Day ...
21/05/2026
Spotify bug n, 20'nci y l d n m m z kutlad m z bu y lda, finans camias na, i modelimiz, r n stratejimiz ve uzun vadeli vizyonumuz hakk nda daha detayl ...
21/05/2026
Two new Story Packs join orchestral instrument line-up
Sonuscore have just introduced two new additions to The Score, marking the instrument's first maj...