
If it was a long time ago, password changes may well be due. While that may seem like overkill, users of Spotify and other online services should ask themselves when they last changed their passwords. Security experts often say that passwords for any account should be changed every one to three months.

While there is no reason to believe Spotify has been the victim of any other breaches or hacks that it is unaware of, there is always the chance and the older a password is the more likely it is to have been exposed. However, the data breach notification coupled with the recent apparent hack should give users pause for thought. Spotify also notes that it has "no reason to believe that any unauthorized use of the information has or will occur." Users who have not received a password reset email and who have been able to continue using Spotify without needing to reset their password should not have been affected by the breach. when we try to do a password reset, we get the message that a mail was sent with more information. He only knows the emailaddress that was used during registration of his account.

As noted, Spotify has contacted the users affected by the breach and had them reset their passwords. i have a customer who's desparately trying to connect to his spotify account but doesn't succeed because he doesn't know his password & username.
