How a distributor's ISRC block becomes your fraud exposure.
ISRCs issued within the same registration block can be exploited to mask artificial streams across a catalogue. Most labels do not understand the issuance chain - therefore cannot identify the attack vector.
This piece is in the research pipeline. The thesis and the questions we are answering are below. The fully-drafted article will publish when the Office has finished working through the literature. Subscribe via the contact form to be notified when it lands.
- Thesis
The argument.
The ISRC issuance chain is opaque to most labels. Distributors batch-issue ISRCs within registration blocks; fraudsters exploit the proximity to mask manipulation across multiple catalogue entries. This paper walks through the issuance chain from IFPI to national agencies to distributors, explains the attack vector, and lists the controls a label can apply at upload time.
- Research questions
What we are answering.
How are ISRCs issued - the registration chain from IFPI to distributors?
What is known about how fraudsters exploit ISRC registration patterns?
How do distributors batch-issue ISRCs and what are the audit-trail implications?
What is the PPL / GRid standard for ISRC validation and what gaps exist?
Are there cases where ISRC manipulation was used to disguise fraudulent streaming at catalogue level?
What controls do DSPs apply at ISRC level vs. account level?
- Tone & format
How it will read.
Technical method paper. Audience is label ops, distribution compliance, rights management.
Privacy notice
Cookies on Music Intel.
We use storage technologies to remember your settings and, only with your consent, measure on-page engagement or advertising performance. External services such as the merch shop provide their own privacy controls.
Strictly necessaryAlways on
Essential cookies for the site to function. Cannot be disabled.
musicata_sessionSession
Maintains your login state across pages.
musicata_consent1 year
Remembers your cookie preferences.
mi_ec_dismissed30 days
Remembers that you dismissed an email sign-up prompt.
Campaign email hand-offSession
Stores an email you submit only for the current tab while an email gate, pre-save return or linked download completes.
Functional
Remembers preferences and settings for a more personalised experience. Embedded services may provide separate privacy controls.
musicata_prefs1 year
Stores your UI preferences (theme, display settings).
Performance
Helps us understand on-site use and filter automated traffic. Groove and Google Analytics load only after you choose this category.
musicata_engagement24 hours
First-party. Tracks scroll depth and active time on customer sites.
mus_vid1 year
First-party pseudonymous visitor identifier used by Groove for on-site engagement analysis and bot filtering.
mus_utmSession
Session storage for campaign-source information such as UTM, gclid and fbclid values.
Device signalsWith consent
Groove derives pseudonymous hashes from browser and device capabilities, including canvas, WebGL and audio signals, and records interaction summaries. These are not loaded under Essential only.
_ga2 years
Google Analytics. Distinguishes unique visitors. IP-anonymised.
_ga_*2 years
Google Analytics. Persists session state for our GA4 property.
_gid24 hours
Google Analytics. Distinguishes users (legacy / fallback).
Marketing
Third-party pixels used to measure advertising effectiveness. They load only after you choose this category and are also subject to the provider's privacy terms.
_fbp90 days
Meta Pixel. Identifies the browser for ad measurement.
_fbc90 days
Meta Pixel. Stores click identifiers from Facebook ad links.
TikTok Pixel identifiersUp to 13 months
Customer-configured TikTok campaign measurement on eligible campaign pages. It loads only after Marketing consent.
BulletinIndustry intelligence
Stay ahead of the industry.
Field notes, market research, and product updates from the Music Intel editorial desk. No noise.