What is documented
Unauthorised music uploads exist. Spotify provides a reporting route for rightsholders whose music has been uploaded without permission.[2] Spotify has also documented malicious releases being attached to the wrong artist profile, alongside accidental metadata mix-ups.[1]
Those are real identity and attribution risks. They justify monitoring and investigation.
What is not established
The public sources reviewed for this note do not establish that a duplicate upload, by itself, redirects royalties from the authorised owner. They do not establish the frequency of such events or a total loss figure. Spotify's re-upload guidance shows that matching audio and metadata can cause tracks to be linked in some legitimate re-delivery cases, but it does not describe a royalty-diversion mechanism.[3]
For that reason, Music Intel treats duplicate-upload royalty hijacking as a threat hypothesis to test against case evidence, not as a proven industry-wide fraud category.
The attack surface
A recording moves through distributor delivery, platform ingestion, artist-profile mapping and rights administration. Each stage relies on identifiers and metadata. DDEX guidance shows that recording ownership is represented through specific release metadata, including the phonogram copyright notice.[4]
An investigation should therefore compare the audio, ISRC history, ownership notices, distributor delivery records, artist mapping, release dates and payment reports. A mismatch is a question. It is not proof of intent.
Controls a rightsholder can apply
- Keep the original delivery record and distributor acknowledgement.
- Monitor unexpected releases and profile attachments.
- Record ISRC, audio fingerprint, ownership notice and release history together.
- Use the platform's official reporting route for an unauthorised upload.
- Preserve screenshots, URLs, timestamps and responses before a listing changes.
- Do not allege diversion until payment and delivery evidence supports it.
The defensible conclusion is narrow: recording identity can be abused, public controls acknowledge that risk, and careful evidence collection is required before describing the financial consequence.
Primary and official sources.
- Introducing artist profile protection Supports: Spotify documents malicious release attachment and metadata mix-ups affecting artist profiles.
- Re-uploading music Supports: Spotify may link re-uploaded tracks when audio and metadata match, preserving play counts in qualifying cases.
- PLine and CLine Supports: DDEX guidance explains how sound-recording ownership information is expressed through the phonogram copyright notice.
Take this to BlackBox Royalty Investigator
BlackBox Royalty Investigator checks delivery records, ISRC history and ownership notices against each other, the same evidence trail this piece sets out for spotting an unauthorised upload.
