What is documented
Unauthorised music uploads exist. Spotify provides a reporting route for rightsholders whose music has been uploaded without permission.[2] Spotify has also documented malicious releases being attached to the wrong artist profile, alongside accidental metadata mix-ups.[1]
Those are real identity and attribution risks. They justify monitoring and investigation.
What is not established
The public sources reviewed for this note do not establish that a duplicate upload, by itself, redirects royalties from the authorised owner. They do not establish the frequency of such events or a total loss figure. Spotify's re-upload guidance shows that matching audio and metadata can cause tracks to be linked in some legitimate re-delivery cases, but it does not describe a royalty-diversion mechanism.[3]
For that reason, Music Intel treats duplicate-upload royalty hijacking as a threat hypothesis to test against case evidence, not as a proven industry-wide fraud category.
The attack surface
A recording moves through distributor delivery, platform ingestion, artist-profile mapping and rights administration. Each stage relies on identifiers and metadata. DDEX guidance shows that recording ownership is represented through specific release metadata, including the phonogram copyright notice.[4]
An investigation should therefore compare the audio, ISRC history, ownership notices, distributor delivery records, artist mapping, release dates and payment reports. A mismatch is a question. It is not proof of intent.
Controls a rightsholder can apply
- Keep the original delivery record and distributor acknowledgement.
- Monitor unexpected releases and profile attachments.
- Record ISRC, audio fingerprint, ownership notice and release history together.
- Use the platform's official reporting route for an unauthorised upload.
- Preserve screenshots, URLs, timestamps and responses before a listing changes.
- Do not allege diversion until payment and delivery evidence supports it.
The defensible conclusion is narrow: recording identity can be abused, public controls acknowledge that risk, and careful evidence collection is required before describing the financial consequence.
How this note was prepared.
- Evidence class
- research brief
- Method
- Threat-model review of Spotify artist-protection and support documentation plus DDEX guidance on recording ownership metadata. Confirmed platform behaviours are separated from Music Intel hypotheses requiring case evidence.
- Limitations
- The reviewed public sources do not establish how often unauthorised duplicates occur, whether a duplicate upload alone redirects royalties, or the scale of any resulting loss. This article must not be read as proof of a specific fraud event.
Primary and official sources.
- Introducing artist profile protection Supports: Spotify documents malicious release attachment and metadata mix-ups affecting artist profiles.
- Re-uploading music Supports: Spotify may link re-uploaded tracks when audio and metadata match, preserving play counts in qualifying cases.
- PLine and CLine Supports: DDEX guidance explains how sound-recording ownership information is expressed through the phonogram copyright notice.
