AI streaming fraud: musician gets 18 months for $10M scam

AI streaming fraud: musician gets 18 months for $10M scam

A musician from North Carolina has been sentenced to 18 months in federal prison for a streaming royalty scheme that pulled more than $10 million out of Spotify, Apple Music, Amazon Music and YouTube Music. He used AI-generated songs and automated bot accounts to do it.

Michael Smith, 54, was indicted in September 2024 and pleaded guilty in March. Prosecutors said he artificially inflated the play counts of his tracks from 2017 to 2024.

Along with the prison term, the court ordered Smith to forfeit $8,091,843.64 and to serve two years of supervised release after his sentence.

Hundreds of thousands of songs, billions of plays

Court documents describe a scheme built on volume. Smith bought hundreds of thousands of AI-generated songs from an accomplice and uploaded them to the major streaming services. He then pointed automated bots at the catalogue, and those bots played the tracks billions of times.

He did not act alone. According to the filings, he had help from the Chief Executive Officer of an AI music company and from a music promoter who has not been named.

To get past the platforms' anti-fraud systems, the bots connected through virtual private networks (VPNs). This hid where the traffic was really coming from. At its height, the operation ran more than 1,000 bot accounts.

The math behind the scheme

Smith kept notes on how the operation made money. On October 20, 2017, he emailed himself a financial breakdown. It showed 52 cloud service accounts, each running 20 bot accounts.

By his own estimates at the time, each bot could play about 636 songs a day. That added up to roughly 661,440 streams daily. At an average royalty of half a cent per stream, he calculated:

  • daily earnings of $3,307.20
  • monthly earnings of $99,216
  • annual earnings of more than $1.2 million

The approach changed as the platforms tightened their controls. On October 4, 2018, Smith wrote to his accomplices that "we need to get a TON of songs fast to make this work around the anti fraud policies these guys are all using now."

In the same message he explained the logic. The group needed "a TON of content with small amounts of Streams" so that no single track drew attention from "the powers that be."

The strategy was simple. Spreading plays thinly across a huge catalogue meant no individual song would stand out as suspicious, even while the overall numbers kept climbing.

Bigger than Taylor Swift on family plans

The Department of Justice gave an example of the scale. In April 2023, Taylor Swift's entire catalogue received 9.3 million streams on YouTube Music from family plan accounts. In the same month, Smith's bot accounts used family plans to stream his AI-generated music 80.9 million times.

Smith was open about the results in private. In a February 2024 email, he told accomplices that the songs had produced "over 4 billion streams and $12 million in royalties since 2019."

"By flooding music streaming platforms with automated bots in the place of consumers, and fake songs in the place of creativity, Smith robbed millions in royalty payments from genuine artists and their fans," said U.S. Attorney Jamie McDonald.

That last point matters for how streaming payouts work. Royalties come from a shared pool, so fake plays do more than generate money for the fraudster. They take a slice of revenue that would otherwise have gone to real musicians.

Why It Matters

At first glance this looks like a music industry story. The techniques, though, will be familiar to anyone who works on fraud detection. Smith combined cheap synthetic content, automation at scale, cloud accounts and VPNs to make bot traffic look like ordinary listeners. His 2018 email shows he adapted directly to the platforms' anti-fraud rules. He spread activity thinly enough to stay below whatever thresholds he thought were being watched.

This suggests that generative AI's main contribution here was not technical sophistication but supply. Hundreds of thousands of tracks would be hard to produce any other way. We have seen similar pressure elsewhere, such as Google pausing its OSS bug bounty after a flood of AI-generated submissions. Systems designed around human-scale input struggle when the input becomes effectively unlimited. It also fits the broader view that attackers currently lead defenders in putting AI to practical use.

The scheme also ran for roughly seven years before the indictment, which raises questions about how well the platforms' own controls held up. It is worth watching whether streaming services publicly change how they detect low-volume, high-spread manipulation. Another open question is whether prosecutors take action against the accomplices named in the court documents, including the AI music company executive.