- Field Notes / No. 027
No. 027 Chief Creative Office BlackBox Royalty Investigator Published research brief 5 min read

Unauthorised uploads and recording identity abuse: what the public evidence establishes

Unauthorised uploads and malicious artist-profile attachments are documented. Their frequency and any direct royalty-diversion mechanism are not established by the public sources reviewed here.

Published by Music Intel · · Updated

What is documented

Unauthorised music uploads exist. Spotify provides a reporting route for rightsholders whose music has been uploaded without permission.[2] Spotify has also documented malicious releases being attached to the wrong artist profile, alongside accidental metadata mix-ups.[1]

Those are real identity and attribution risks. They justify monitoring and investigation.

What is not established

The public sources reviewed for this note do not establish that a duplicate upload, by itself, redirects royalties from the authorised owner. They do not establish the frequency of such events or a total loss figure. Spotify's re-upload guidance shows that matching audio and metadata can cause tracks to be linked in some legitimate re-delivery cases, but it does not describe a royalty-diversion mechanism.[3]

For that reason, Music Intel treats duplicate-upload royalty hijacking as a threat hypothesis to test against case evidence, not as a proven industry-wide fraud category.

The attack surface

A recording moves through distributor delivery, platform ingestion, artist-profile mapping and rights administration. Each stage relies on identifiers and metadata. DDEX guidance shows that recording ownership is represented through specific release metadata, including the phonogram copyright notice.[4]

An investigation should therefore compare the audio, ISRC history, ownership notices, distributor delivery records, artist mapping, release dates and payment reports. A mismatch is a question. It is not proof of intent.

Controls a rightsholder can apply

  • Keep the original delivery record and distributor acknowledgement.
  • Monitor unexpected releases and profile attachments.
  • Record ISRC, audio fingerprint, ownership notice and release history together.
  • Use the platform's official reporting route for an unauthorised upload.
  • Preserve screenshots, URLs, timestamps and responses before a listing changes.
  • Do not allege diversion until payment and delivery evidence supports it.

The defensible conclusion is narrow: recording identity can be abused, public controls acknowledge that risk, and careful evidence collection is required before describing the financial consequence.

- Evidence note

How this note was prepared.

Evidence class
research brief
Method
Threat-model review of Spotify artist-protection and support documentation plus DDEX guidance on recording ownership metadata. Confirmed platform behaviours are separated from Music Intel hypotheses requiring case evidence.
Limitations
The reviewed public sources do not establish how often unauthorised duplicates occur, whether a duplicate upload alone redirects royalties, or the scale of any resulting loss. This article must not be read as proof of a specific fraud event.
- Sources

Primary and official sources.

  1. Introducing artist profile protection
    Spotify for Artists · official platform · Published 15 March 2026 · Accessed 10 August 2026
    Supports: Spotify documents malicious release attachment and metadata mix-ups affecting artist profiles.
  2. Reporting music uploaded without your permission
    Spotify for Artists Support · official platform · Accessed 10 August 2026
    Supports: Spotify provides a process for rightsholders to report music uploaded without permission.
  3. Re-uploading music
    Spotify for Artists Support · official platform · Accessed 10 August 2026
    Supports: Spotify may link re-uploaded tracks when audio and metadata match, preserving play counts in qualifying cases.
  4. PLine and CLine
    DDEX · industry standard · Accessed 10 August 2026
    Supports: DDEX guidance explains how sound-recording ownership information is expressed through the phonogram copyright notice.