August Cloaked In Security: The predator hiding in a music app

Edited

The app you trusted because it "wasn't social media" is the one to watch

She was a diligent parent: her 13-year-old had no social media, no App Store, no browser, heavy Screen Time limits. Every channel a predator is "supposed" to use was closed. And still, for two months, someone posing as a teen still built a relationship with her daughter and extracted personal photos and details — entirely through Apple Music.

No chat window, no DMs, no notifications. Communication ran through playlist titles, descriptions, usernames, collaborative playlists, and uploaded artwork. Spotify has the same features. This isn’t a music-app story — it’s a covert channel story: legitimate features repurposed for communication parents aren’t trained to monitor. That is exactly the blind spot a targeted actor wants in a high-profile family.

The takeaway: "Locked down" is not "monitored." Any app with a shared text field — games, streaming, fitness — can be a messaging channel.

Have your team book time with us to extend protection to their families. Sharable tips below:

Sharable Best Practices:

  • Audit the "non-social" apps. Check music, gaming, and streaming accounts for public profiles, follower lists, playlist titles/descriptions, collaborative playlists, and personal photos used as artwork.

  • Treat any shared field as a chat. If two people can edit or view the same field, monitor it like a messaging app.

  • Make privacy the default. Set profiles private, disable public discoverability and following, and turn off collaborative features you don’t need.

  • Talk, don’t just toggle. Ask children who they interact with even on "just for music" apps, and watch for unfamiliar abbreviations or coded language.

Be Aware: ShinyHunters Remains Active

The ShinyHunters extortion group continues to target organizations across industries, with recent claims involving several well-known brands. While details of many incidents remain under investigation, the group's activity reinforces the importance of strong identity protections and rapid detection of credential abuse following third-party breaches.