Get all your news in one place.
100’s of premium titles.
One app.
Start reading
The Guardian - UK
The Guardian - UK
Technology
Alex Hern

Spotify hit by 'malvertising' in app

The Spotify attack was reported by multiple users on social media.
The Spotify attack was reported by multiple users on social media. Photograph: Andrew Matthews/PA

Spotify has become the latest service to be hit by “malvertising”, after a malicious advert pushed through the free tier of the music streaming site started opening “questionable” website pop-ups for some users.

The attack was reported by multiple users on social media throughout Wednesday morning. For most, it simply resulted in pop-up windows opening, but a few users reported attempted malware installations further down the chain.

In response to a user question, Spotify confirmed the reports. “We’ve identified an issue where a small number of users were experiencing a problem with questionable website pop-ups in their default browsers as a result of an isolated issue with an ad on our Free tier. We have now identified the source of the problem and have shut it down. We will continue to monitor the situation.”

Malvertising has hit some of the biggest websites, including Yahoo, the New York Times and the BBC. The issue comes because most large sites sell advertising space through third-party resellers, who pull in code for the adverts on the fly based on an open auction. If malicious code can be smuggled on to the ad server, it can often be sent to multiple sites at once.

The rise of malvertising has been a key driver in the use of ad-blocking software, which can prevent the adverts being loaded in the first place. But in-app adverts, of the sort that Spotify uses, are harder to block. Another alternative for users annoyed by Spotify adverts: sign up for the service’s premium tier, at £9.99 a month.

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.