惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google Online Security Blog
Google Online Security Blog
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
V
V2EX
雷峰网
雷峰网
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
F
Full Disclosure
Y
Y Combinator Blog
V
V2EX - 技术
Attack and Defense Labs
Attack and Defense Labs
S
Security @ Cisco Blogs
Schneier on Security
Schneier on Security
Microsoft Azure Blog
Microsoft Azure Blog
SecWiki News
SecWiki News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
量子位
PCI Perspectives
PCI Perspectives
S
Secure Thoughts
D
Darknet – Hacking Tools, Hacker News & Cyber Security
AWS News Blog
AWS News Blog
Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
K
Kaspersky official blog
B
Blog
A
Arctic Wolf
Hacker News: Ask HN
Hacker News: Ask HN
L
LangChain Blog
T
Tor Project blog
P
Privacy & Cybersecurity Law Blog
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
D
Docker
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
The Last Watchdog
The Last Watchdog
S
Security Affairs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Privacy International News Feed
Simon Willison's Weblog
Simon Willison's Weblog

Security Latest

The FCC Wants to Kill Burner Phones Grok Is Still Hosting Sexualized Deepfakes of Famous Women Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick Wrongful Arrest Exposes Failures in One of the Oldest Police Face-Recognition Tools in the US Soccer Fans, You’re Being Watched Mapping Every Flock License Plate Reader Near US World Cup Stadiums Amnesty International Warns That World Cup Fans Face Potential Human Rights Violations Anthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of You Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report All the Ways Europe Is Ditching American Technology Crypto-Funded Chinese Peptide Labs Are Booming Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity Android Is Fighting Phone Scams With a New Feature to Prove Who’s Calling The Manhattan Institute Helped Kill DEI. Now It’s Coming for Protests The Romance Scammer Who Made a Small Fortune Posing as a WWE Superstar Websites Can Now Spy on You Through Your Hard Drive Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow The White House’s Aliens.gov Site Brags That ICE Arrested More Than 700 US Citizens The Pentagon Knew Enemies Could Track Troops’ Phones for Years. Now They Are Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing Attacks Internet Starts to Return in Iran After 3-Month Blackout US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows The AI Era Is Creating a Bug-Hunting Arms Race The FBI Wants ‘Near Real-Time’ Access to US License Plate Readers ‘Creepy’ Listening Tool for Targeted Ads Didn’t Actually Work, FTC Says A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale The EU Is Going Through a Trump-Fueled Breakup With Big Tech A Bipartisan Amendment Would End Police License Plate Tracking Nationwide Madison Square Garden Bans Lawyer Representing New York Cop Injured at a Boxing Match Data Brokers’ and AI Firms’ Opt-Out Forms Are Built to Fail, Report Finds You Can Get Some of Your Nudes Removed From the Internet Under a New Law An ICE Firearms Trainer Was Involved in At Least 4 Deadly Shootings Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording Your iPhone Gets Stolen. Then the Hacking Begins DHS Plans Experiment Running ‘Reconnaissance’ Drones Along the US-Canada Border WhatsApp Adds Meta AI Chats That Are Built to Be Fully Private Foxconn Ransomware Attack Shows Nothing Is Safe Forever Iran Is Using Tiny ‘Mosquito’ Boats to Shut Down the Strait of Hormuz Hackable Robot Lawn Mower Unlocks a New Nightmare How to Disable Google's Gemini in Chrome Cybercriminals Are Complaining About AI Slop Flooding Their Forums DHS Demanded Google Surrender Data on Canadian’s Activity, Location Over Anti-ICE Posts Disneyland Now Uses Face Recognition on Visitors OpenAI Rolls Out ‘Advanced’ Security Mode for At-Risk Accounts Exposed Data Illustrates the Nightmare Scenario for a Stalkerware Victim The Race Is on to Keep AI Agents From Running Wild With Your Credit Cards California Engineer Identified in Suspected Shooting at White House Correspondents Dinner Discord Sleuths Gained Unauthorized Access to Anthropic’s Mythos Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet AI Tools Are Helping Mediocre North Korean Hackers Steal Millions Mozilla Used Anthropic’s Mythos to Find and Fix 271 Bugs in Firefox Meta Is Sued Over Scam Ads on Facebook and Instagram They Built a Legendary Privacy Tool. Now They’re Sworn Enemies The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad It Takes 2 Minutes to Hack the EU’s New Age-Verification App Republican Mutiny Sinks Trump's Push to Extend Warrantless Surveillance The Shocking Secrets of Madison Square Garden’s Surveillance Machine Europe’s Online Age Verification App Is Here The Deepfake Nudes Crisis in Schools Is Much Worse Than You Thought In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market The FCC Has a Fast Lane for Complaints About Trump’s Media Critics Meta Is Warned That Facial Recognition Glasses Will Arm Sexual Predators The Dumbest Hack of the Year Exposed a Very Real Problem Your Push Notifications Aren’t Safe From the FBI How the Internet Broke Everyone’s Bullshit Detectors Anthropic’s Mythos Will Force a Cybersecurity Reckoning—Just Not the One You Think Politicians Are Spending More Money on Security as They Increasingly Become Targets ‘We Were Not Ready for This’: Lebanon's Emergency System Is Hanging by a Thread Men Are Buying Hacking Tools to Use Against Their Wives and Friends Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything Border Patrol Agents Sold Challenge Coins With ‘Charlotte’s Web’ Characters in Riot Gear Hackers Are Posting the Claude Code Leak With Bonus Malware Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk CBP Facility Codes Sure Seem to Have Leaked Via Online Flashcards ‘Uncanny Valley’: Iran’s Threats on US Tech, Trump’s Plans for Midterms, and Polymarket’s Pop-up Flop What Happens When a Nuclear Site Is Hit? Unmasking the Paramilitary Agents Behind Trump’s Violent Immigration Crackdown Apple Will Push Out Rare ‘Backported’ Patches to Protect iOS 18 Users From DarkSword Hacking Tool Iran Threatens to Start Attacking Major US Tech Firms on April 1 The US Military’s GPS Software Is an $8 Billion Mess The Broken System That Keeps Shipping Crews Stranded in the Strait of Hormuz Iranian Hackers Breached Kash Patel’s Email—but Not the FBI’s How Trump’s Plot to Grab Iran's Nuclear Fuel Would Actually Work
Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcasts
Dell Cameron · 2026-06-12 · via Security Latest

For the past year, Spotify has been quietly purging tens of thousands of podcasts that advertised illegal online pharmacies. A report released Thursday by Senator Maggie Hassan, ranking member of the Joint Economic Committee, faults the company for acting only after news outlets exposed the content and her office spent nearly a year pressing for answers.

None of what it removed was sent to law enforcement, the report says.

Spotify reportedly removed more than 57,000 podcast episodes and 3,000 shows, and took enforcement action against 3,500 accounts, all pushing links to illegal online pharmacies advertising opioids, benzodiazepines, and stimulants for sale without a prescription. Nevertheless, the report frames the cleanup as a moderation failure.

The report leans on one comparison in particular: Spotify acted against more than 3,500 accounts for drug content in 2025 but fewer than 100 the year before. The committee presents the jump as evidence the company moved only after it came under scrutiny. Spotify offered a different explanation: that its older counts are incomplete because, as it says in the report, it changed the way it tracks removals last year.

A handful of the offending podcasts did find an audience. Of the five that drew more than 100 plays, two together pulled around 13,000 streams and walked listeners through buying modafinil, a wakefulness drug, by sending bitcoin. Another, with 125 plays, linked to sites posing as pharmacy marketplaces for cancer and HIV medications. Those were the exceptions, but they pointed to working ways to pay and order.

The numbers are alarming, and the stakes are real, Hassan says: Counterfeit pills bought online are frequently cut with fentanyl, and teenagers are among the most exposed.

“In the age of AI, all online platforms need to deploy sophisticated efforts to continually identify and take down illegal content,” Hassan tells WIRED. “Failure to swiftly detect and remove dangerous content and also report it to law enforcement can lead to harrowing consequences—whether that’s a teenager who buys drugs online that could be laced with deadly fentanyl or a senior who falls for a scam that wipes out their retirement savings.”

Asked about its approach to AI podcasts, Spotify spokesperson Laura Batey says the company “has a long history of working with law enforcement when content violates the law.” She did not say whether Spotify makes proactive referrals to the Drug Enforcement Agency, or how often. Batey said Spotify is still looking into WIRED’s question about whether it tracks clicks on those links.

Spotify told the committee that its practice is to alert authorities only when it identifies a credible threat of serious harm: an imminent risk to someone's life or safety. The podcasts, which it had classified as a search-optimization scheme rather than evidence of actual drug sales, never met that bar, the company said.

While Spotify did not say whether it reports illegal drug activity to the DEA, the report says the company's competitors answer that question directly: Snap regularly makes proactive referrals to the agency, and Meta says it cooperates with law enforcement to combat drug sales. Spotify's position, according to the report, is that, as a licensed-content streaming service, its obligations differ from those of a social network.

At least one of the removed podcasts pointed somewhere law enforcement was already looking. A show the committee flagged in July 2025—listed under a string of nonsense characters and titled to advertise a “licensed online vendor”—linked to a site called Opioidstores.com. That domain was later seized by federal prosecutors in Brooklyn, working with the DEA, the FDA, and other agencies. Spotify removed the podcast but, by its own account, reported nothing.

Of the episodes Spotify removed, the company told the committee, 94 percent drew zero plays and 99 percent had fewer than 10. The shows were barely heard, because reaching Spotify's audience was never the goal, according to the company, which says the actual payload was links buried in episode descriptions and cover art—an effort at exploiting Spotify's standing with search engines to push illicit pharmacy and scam sites up Google’s rankings.

Play counts, though, only measure whether someone listened to the audio, and by Spotify's own account, the audio was never the point. What the operators wanted was for listeners to click the links tucked into episode descriptions and cover art. And Spotify doesn't track those clicks. The company told the committee it monitors link activity only for ads it was paid to run, not for links inside ordinary podcasts. Its numbers can show that almost no one pressed Play but cannot show how many people followed a link to a pharmacy or scam site.

The same fake drug series turned up well beyond Spotify. Committee staff found copies on iHeart, Amazon Music, and Podchaser, several stamped with nearly identical 2021 upload dates. That overlap reflects how podcasting works. Shows are published once, and the various apps all pull from that single source. Removing it from one app does nothing to the original or to the copies running everywhere else.

Amazon Music and Podchaser did not immediately respond to requests for comment; iHeartMedia could not be reached.

Spotify told the committee it has several systems for catching this content. The company keeps a list of drug names and street slang and uses software to spot when a banned user opens a new account. It also runs new and edited episodes through an AI filter before sending questionable ones to human reviewers.

The company pays an outside firm, LegitScript, to review podcasts, though only once every three months. Content that gets pulled is removed from search immediately, Spotify said. Anything still appearing in search results is there because it hasn't found it to break the rules.

Much of this content is now generated by AI. The report points to services that market creative studios for AI podcasting—synthetic hosts, cloned voices, and a method for publishing straight to Spotify. In one case the committee flagged, an AI-generated podcast posing as a real psychiatrist ran episodes walking through benzodiazepines like midazolam and estazolam, drugs the DEA warns are misused by teenagers.

Spotify has built defenses against AI spam, though so far for music rather than podcasts.

In September 2025, Spotify announced new AI protections and said it had removed 75 million spam tracks over the previous year. It told the committee those measures were specific to music and that it has no policy against AI-generated podcasts. The report says a Spotify representative told committee staff the company is not well-positioned to identify AI-made content. A rival, iHeartMedia, went further in November, pledging that the podcasts it publishes are “guaranteed human.”

The problem does not stop at Spotify or even podcast platforms more broadly. The company told the committee that the same search-manipulation spam has spread across the internet, including onto local, state, and federal government websites. And as AI drops the cost of producing it, the content keeps surfacing wherever a trusted domain can be borrowed.