Reused passwords that appears in breaches maybe?
Spotify reacted rapidly and restored my account in few days. But it looks suspicions to me that the attacker was able to change my email without Spotify sending me a confirmation first (my email account was not broken). Also Spotify is missing 2FA that would have prevented this.
From the article: >On Reddit, Callum Dixon wrote: "The same Bergenulo Five keeps being played on my account and I've tried everything - changed my password, logged out of everywhere. I can't stop it!"