Suspicious
Phishings targeting Spotify
Suspicious and active websites
Phishings targeting Spotify
Suspicious and active websites
Active
11
New (7d)
3
Trend (7d)
↑50%
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-09-29 09:30 | 2026-09-29 01:02 | ![]() |
OpenPhish | Details | |
| 2026-09-29 09:30 | 2026-09-27 17:26 | ![]() |
GSB | Details | |
| 2026-09-29 09:30 | 2026-09-25 17:26 | ![]() |
GSB | Details | |
| 2026-09-29 09:30 | 2026-09-18 01:03 | ![]() |
OpenPhish | Details | |
| 2026-09-29 09:30 | 2026-09-17 19:02 | ![]() |
PhishTank | Details | |
| 2026-09-29 09:30 | 2026-08-24 05:25 | ![]() |
GSB | Details | |
| 2026-09-29 09:30 | 2026-07-06 12:07 | ![]() |
TweetFeed | Details | |
| 2026-09-29 09:30 | 2026-07-06 12:07 | ![]() |
TweetFeed | Details | |
| 2026-09-29 09:30 | 2026-06-14 13:01 | ![]() |
OpenPhish | Details | |
| 2026-09-29 09:30 | 2026-06-12 01:01 | ![]() |
OpenPhish | Details | |
| 2026-09-29 09:30 | 2026-05-23 13:01 | ![]() |
OpenPhish | Details |
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://emilycaputi.github.io…
OpenPhish |
![]() |
Details |
| https://be-spotify.com
GSB |
![]() |
Details |
| https://nl-spotify.com
GSB |
![]() |
Details |
| https://a2zapk.dev/1368404-sp…
OpenPhish |
![]() |
Details |
| https://spotify-payment.click
PhishTank |
![]() |
Details |
| https://spotify-plus.com
GSB |
![]() |
Details |
| http://spotifysvotingslink.ct…
TweetFeed |
![]() |
Details |
| http://spotifyzonepro-dl.fwh.…
TweetFeed |
![]() |
Details |
| https://ruddycruzc.github.io/…
OpenPhish |
![]() |
Details |
| http://a2zapk.co/1368404-spot…
OpenPhish |
![]() |
Details |
| http://spotify-client-beta.ve…
OpenPhish |
![]() |
Details |
AIHow to verify a real Spotify URL
- Legitimate Spotify URLs always end in
spotify.com(e.g.www.spotify.com,account.spotify.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Spotify. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
spotify.comfrom your browser bookmark or type the domain manually. - Real Spotify pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.










