Back to Newsroom
Threat Intel

Musician Jailed After AI Bot Network Siphons $10M in Streaming Royalties

A U.S. court sentenced a musician to 18 months in prison for a years-long scheme that used AI-generated songs and thousands of automated bot accounts to siphon over $10 million from Spotify, Apple Music, Amazon Music, and YouTube Music.

Musician Jailed After AI Bot Network Siphons $10M in Streaming Royalties

A North Carolina musician has been sentenced to 18 months in federal prison after orchestrating a multi-year scheme that funneled AI-generated songs through automated bot networks to collect more than $10 million in fraudulent streaming royalties.

What happened

Prosecutors say the musician, working with an AI music company executive and an outside promoter, uploaded hundreds of thousands of AI-generated tracks to major streaming services and then used automated bots — routed through virtual private networks to dodge anti-fraud detection — to stream them billions of times. At its height, the operation ran on more than 1,000 bot accounts spread across dozens of cloud hosting accounts, each capable of streaming hundreds of songs a day, generating an estimated six-figure monthly payout from royalties worth a fraction of a cent per play.

Internal messages cited in court filings show the scheme's architect pushing to add new AI-generated songs quickly, specifically to stay under the radar of platforms' fraud controls, spreading plays thin across a growing catalog rather than concentrating them on a few tracks. By early 2024 he was privately claiming the operation had generated over 4 billion fraudulent streams and roughly $12 million in royalties since 2019 — a scale that, by prosecutors' estimate, saw his bot-streamed catalog outpace the real family-plan streaming activity recorded for an entire A-list artist's discography on the same platform in a single month.

Why it matters

This case is one of the clearest public examples yet of generative AI being used not to write malware or run a phishing lure, but to manufacture fraud volume: AI drove the cost of producing "content" to near zero, while bot infrastructure did the work of faking its popularity. The same pattern — cheap synthetic content paired with automated engagement at scale — is portable well beyond music streaming, and it's exactly the kind of abuse that review processes, rate limits, and anomaly detection are supposed to catch before it reaches real money or real users.

The sentence also shows courts treating AI-enabled fraud as straightforward financial crime rather than a gray area: on top of prison time, the musician was ordered to forfeit more than $8 million and serve two years of supervised release, regardless of the AI layer involved in how the fraud was carried out.

What to do

  • Platforms that pay out based on usage, engagement, or consumption metrics should treat sudden, geographically clustered, or VPN-sourced traffic spikes as a fraud signal, not just a scaling event.
  • Anomaly detection should flag catalogs or accounts whose volume growth far outpaces growth in genuine audience signals — followers, external referrals, repeat human engagement.
  • Any pipeline that accepts bulk AI-generated content should pair moderation with velocity limits; the pacing and volume of uploads is often a stronger fraud indicator than the content itself.
  • Finance and trust-and-safety teams should treat "per-unit micro-payout" business models — streaming, ad impressions, affiliate clicks — as high-value bot-fraud targets and budget for dedicated bot-detection tooling rather than relying on content review alone.
SHARE