AI Music Generator Suno Data Breach Exposes Millions of Users' Sensitive Information

TL;DR
- **Massive Scale:** A cyberattack on AI music generator Suno in November 2025 compromised the personal data of **55.3 million users**, including names, addresses, phone numbers, and emails.
- **Sensitive Data Exposed:** The breach included **tens of thousands of Stripe payment records** containing partial credit card details (expiry dates and last four digits) alongside purchase history.
- **Copyright Implications:** Hackers also stole **Suno’s source code**, which revealed the company allegedly scraped millions of hours of music and lyrics from platforms like YouTube Music, Deezer, and Genius to train its AI models.
AI Music Generator Suno Data Breach Exposes Millions of Users' Sensitive Information
The AI music generation platform Suno is facing a massive security crisis after a cyberattack from late last year was revealed to have compromised the personal information of more than **55 million people**. Although the breach occurred in **November 2025**, the incident remained undisclosed to the public until July 2026, when independent news outlet 404 Media reported on the stolen dataset.
The data breach notification service **Have I Been Pwned (HIBP)** added **55,282,226 unique email addresses** to its database on July 20, marking the first concrete glimpse into the scale of the theft. Suno has not yet publicly disclosed the cyberattack or notified the affected individuals that their information was taken, despite the magnitude of the exposure.
What Data Did Hackers Steal?
The compromised dataset is extensive, containing a wide array of personally identifiable information (PII). According to HIBP, the stolen data includes:
- **Names** and **physical addresses**
- **Email addresses** and **phone numbers** (specifically where used for sign-up)
- **Purchase records** detailing user transactions
A particularly concerning aspect of the breach involves financial data. The attack pulled in **tens of thousands of Stripe records** connected to real purchases. These records contained names, physical addresses, purchase amounts, and **partial credit card data**, including the card type, expiry date, and the **last four digits**.
Suno has maintained that it does not store full credit card numbers and that the company "does not have access to customers' full credit card numbers in Stripe." However, the exposure of partial card details and purchase history still poses significant risks for fraud and identity theft.
Source Code Theft Reveals Alleged Copyright Scraping
Beyond user data, the hacker successfully accessed **Suno’s source code repositories**, uncovering internal evidence of how the company built its training datasets. The stolen code revealed that Suno allegedly scraped enormous volumes of audio and text content from across the web to train its AI models.
Key dataset statistics extracted from the code comments indicate systematic scraping operations that pulled hundreds of thousands of hours of content, including:
- **113,879 hours** of YouTube Music content
- **152,162 hours** of tagged YouTube Music
- **17,615 hours** of Genius HQ lyrics
- **12,287 hours** of Deezer content
- **62,117 hours** of Pond5 music
- Roughly **1 million hours** of podcasts sourced via PodcastIndex
This revelation is critical because several major record labels are currently suing Suno, claiming that its mass-scraping efforts violate copyright law. The leaked source code provides detailed internal documentation that could serve as evidence in these ongoing legal battles.
Suno’s Response and the Delayed Disclosure
Suno has responded to the reports by downplaying the severity of the incident. A company spokesperson told CNET that the breach "primarily involved outdated source code that is no longer in use at Suno" and claimed that **no sensitive personal information was compromised**. The company further concluded that, under current privacy laws, it did not need to notify individual users.
Critics and security experts argue that the disclosure delay is unacceptable. The incident surfaced publicly in **July 2026**, eight months after it occurred in November 2025. Security researchers note that the attack likely utilized a **supply chain attack** in November to access an employee's credentials, allowing the hacker to infiltrate the company's systems.
Risks for Affected Users and Industry Implications
For the **55.3 million affected users**, the risks are immediate and tangible. The exposure of phone numbers, addresses, and partial payment data creates a high risk for **identity theft** and targeted phishing attacks. Users who signed up with their phone numbers are particularly vulnerable, as their contact details were explicitly included in the breach.
The breach also highlights broader vulnerabilities in the AI industry. The fact that a hacker could access both customer data and proprietary source code suggests potential gaps in Suno's security infrastructure. Furthermore, the revelation of the scraping operations adds a new layer of complexity to the legal challenges Suno faces, potentially undermining the company's claims that its models were trained solely on "publicly available music files."
As the legal and security fallout continues, Suno remains the only major AI music generator to face such a dual crisis of massive data loss and exposed copyright controversies simultaneously.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!