Spammers built a fake podcast empire on Spotify — not to be heard, but to hijack the platform's search authority.
A joint congressional report describes an operation that seeded tens of thousands of fake podcast listings on Spotify. The shows were never meant to be played. Spammers packed the metadata with keywords tied to prescription drugs and counterfeit pharmaceuticals, exploiting Spotify's domain authority to surface those pages in search engine results. Clicks landed visitors not on episodes but on illegal pharmacy and scam sites.
The technique — domain authority hijacking — is a well-worn SEO manipulation tactic, but applying it to podcast metadata is a meaningful escalation. Spotify's open ingestion model, which lets anyone publish via RSS, creates a low-friction surface that content moderation wasn't designed to police; platforms have historically focused on what's said inside an audio file, not on whether the listing itself is functioning as link-farm infrastructure. A congressional report adds weight that press coverage alone rarely does, and suggests this has crossed the threshold from platform nuisance to potential liability question.
Spotify isn't uniquely vulnerable here — Apple Podcasts and YouTube face the same structural problem — but the scale described in the report, tens of thousands of listings, suggests the operation ran without meaningful friction for long enough that calling it an oversight is generous.
