A Musician’s Scheme Exposed: $10 Million in Streaming Royalties Scammed Using AI Bots
In a brazen and audacious scheme, a North Carolina musician has been sentenced to 18 months in prison for collecting over $10 million in royalties from major music streaming platforms. Michael Smith, 54, pleaded guilty to inflating his songs’ listening stats between 2017 and 2024 using artificial intelligence (AI) bots and virtual private networks (VPNs).
To carry out the scheme, Smith collaborated with an AI music company CEO and a music promoter to upload hundreds of thousands of AI-generated songs to platforms like Spotify, Apple Music, Amazon Music, and YouTube Music. He then used automated bots to stream these tracks billions of times, connecting to the platforms using VPNs to evade detection by anti-fraud systems.
At its peak, Smith employed over 1,000 bot accounts, each capable of streaming around 636 songs per day. This translated to daily earnings of $3,307.20, monthly earnings of $99,216, and annual earnings exceeding $1.2 million. In an email sent to accomplices in October 2018, Smith emphasized the need for “a TON of content with small amounts of Streams” to avoid raising suspicions.
The scheme’s scope is staggering, as evidenced by its impact on genuine artists and fans. According to the Department of Justice, Taylor Swift’s entire catalogue received 9.3 million streams on YouTube Music in April 2023, while Smith’s bot accounts fraudulently streamed his AI-generated music a whopping 80.9 million times during the same month.
Smith’s scheme has been described as “robbing millions in royalty payments from genuine artists and their fans” by U.S. Attorney Jamie McDonald. In addition to his prison sentence, Smith was ordered to pay $8,091,843.64 in forfeiture and face two years of supervised release.
This case highlights the dangers of using AI-powered attacks for personal gain. As we become increasingly reliant on AI-driven systems, it’s essential to recognize the potential risks and take proactive measures to prevent such schemes from succeeding. This includes implementing robust anti-fraud systems, monitoring streaming activity closely, and staying vigilant against attempts to manipulate streaming platforms.
To mitigate similar threats in the future, cybersecurity professionals must develop a comprehensive security blueprint that addresses AI-powered attacks head-on. This involves understanding the tactics used by attackers, identifying vulnerabilities, and developing effective countermeasures. By doing so, we can prevent further exploitation of music streaming platforms and protect genuine artists from financial loss.
Source: Bleeping Computer — 2026-10-07