All posts

Suno breach exposed 55M users' data, source code stolen

Huma ShaziaJuly 25, 2026 at 10:01 AM4 min read
Suno breach exposed 55M users' data, source code stolen

Key Takeaways

Suno Hack Exposed 55 Million Users and Its Biggest AI Secret

Suno breach exposed 55M users' data, source code stolen
Source: TechCrunch
  • Have I Been Pwned confirmed 55.3 million Suno accounts were compromised in November 2025
  • Stolen data includes names, addresses, phone numbers, and partial payment card details from Stripe
  • Leaked source code allegedly shows Suno scraped songs from Deezer, Genius, and YouTube to train its AI

The Suno data breach from November 2025 affected 55.3 million users, according to Have I Been Pwned, which obtained a copy of the stolen dataset. The breach notification service revealed that hackers stole customer names, physical addresses, email addresses, phone numbers, purchase records, and partial payment card numbers pulled from Suno's Stripe account.

Suno, the AI-powered music generation platform, has not publicly disclosed the attack or notified affected users directly. The company only confirmed the incident after TechCrunch reached out for comment. Spokesperson Rachel Racusen did not dispute the 55.3 million figure but offered no explanation for why Suno has kept quiet for eight months.

Advertisements

What data did hackers steal from Suno?

The breach exposed more than basic account credentials. According to Have I Been Pwned's analysis of the dataset, attackers accessed Suno's Stripe integration and extracted partial payment card numbers along with card expiry dates. Combined with names, phone numbers, and physical addresses, this creates a substantial identity theft risk for affected users.

The stolen source code may prove even more damaging to the company. Independent outlet 404 Media, which first reported the breach, found evidence in the code suggesting Suno scraped millions of songs and lyrics from Deezer, Genius, and YouTube to train its AI models. Several major record labels are already suing Suno over alleged copyright violations, and this leak hands them potential evidence.

Also Read
Suno data breach exposes 55M accounts, claims security expert

Earlier coverage of the initial breach disclosure

Why hasn't Suno notified affected users?

Eight months after the breach, Suno has not posted any disclosure on its website. Co-founder Mikey Shulman did not respond to TechCrunch's requests for comment. When pressed, the company provided no evidence of any communication sent to users about the incident.

This silence raises legal questions. Data breach notification laws in the US vary by state, but California's CCPA requires companies to notify residents without unreasonable delay. The EU's GDPR mandates disclosure within 72 hours for breaches affecting European users. With 55 million accounts compromised, Suno almost certainly has users in both jurisdictions.

The Palo Verde Diversion Dam on the Colorado River near Ehrenberg, Arizona.
The Palo Verde Diversion Dam on the Colorado River near Ehrenberg, Arizona.

The copyright angle complicates everything

Suno faces lawsuits from major record labels claiming the company's AI models were trained on copyrighted material without permission. The leaked source code, if authentic, could substantiate those claims by showing exactly which streaming platforms Suno allegedly scraped.

Sam Altman, chief executive officer of OpenAI, right, departs the New York Times DealBook Summit at Jazz at Lincoln Center in New York, US, on Wednesday, Dec. 4, 2024.
Sam Altman, chief executive officer of OpenAI, right, departs the New York Times DealBook Summit at Jazz at Lincoln Center in New York, US, on Wednesday, Dec. 4, 2024.

The New York Times is currently suing OpenAI over similar training data concerns, arguing that ChatGPT was trained on copyrighted articles. Japanese publishers, including Studio Ghibli, have demanded that OpenAI stop using their work. Suno now joins this growing list of AI companies whose internal practices may be exposed through security failures rather than legal discovery.

Also Read
Android 17's Intrusion Logging tracks suspicious app behavior

How mobile platforms are improving breach detection

Advertisements

What should affected users do now?

Users who created a Suno account should assume their data was compromised. Check Have I Been Pwned directly to confirm if your email appears in the breach. Change your Suno password immediately, and if you reused that password elsewhere, change it everywhere.

The partial payment card exposure is concerning but limited. Card numbers were truncated, so attackers cannot make direct charges. Still, monitor your credit card statements for unusual activity and consider placing a fraud alert with the major credit bureaus if you provided Suno with your physical address.

AI startups face mounting security scrutiny

The Suno breach fits a pattern. Fast-growing AI startups prioritize product velocity over infrastructure hardening, then scramble when attackers exploit the gaps. AegisAI, founded by former Google security executives, just raised $36 million specifically to address AI-driven security threats. The market clearly sees opportunity in protecting companies that have neglected defense.

AegisAI co-founders Cy Khormaee and Ryan Luo
AegisAI co-founders Cy Khormaee and Ryan Luo

For enterprise buyers evaluating AI music tools, Suno's handling of this breach should factor into procurement decisions. A company that cannot secure user data or communicate transparently after an incident presents ongoing risk.

ℹ️

Logicity's Take

Suno's eight-month silence transforms a security incident into a trust crisis. CTOs evaluating AI music generation should now compare Suno against alternatives like Udio or Google's MusicLM, factoring security posture into the decision. The source code leak also hands record labels a gift in their copyright lawsuits. If the code proves Suno scraped copyrighted content, the company faces both regulatory fines for the breach and potentially massive damages for infringement. This is what happens when hypergrowth outpaces both security and legal compliance.

Data ExposedRisk LevelUser Action Required
Email addressesHigh (phishing target)Watch for suspicious emails, enable 2FA
Physical addressesMedium (identity theft)Monitor credit reports
Phone numbersMedium (SIM swap risk)Consider carrier PIN
Partial card numbers + expiryLow (cannot charge directly)Monitor statements
Purchase historyLowNo immediate action

Frequently Asked Questions

How do I check if my data was in the Suno breach?

Visit Have I Been Pwned and enter your email address. The site now includes the Suno breach data and will confirm if your account was compromised.

Can hackers use my partial credit card number from Suno?

No, partial card numbers cannot be used for direct purchases. However, combined with other stolen data like your name and address, this information could support phishing or social engineering attacks.

Is Suno required to notify users about the breach?

Likely yes, depending on where users reside. California's CCPA and the EU's GDPR both mandate breach notifications, though enforcement varies. Suno has not publicly explained why it has remained silent.

Does the source code leak affect Suno's copyright lawsuits?

It could help the record labels suing Suno. If the leaked code shows Suno scraped copyrighted songs from Deezer, Genius, and YouTube, plaintiffs may use this as evidence of willful infringement.

When did the Suno breach happen?

The attack occurred in November 2025. It was only publicly disclosed in July 2026 after 404 Media reported on the incident and Have I Been Pwned obtained the stolen dataset.

Also Read
Zilliqa reports cold wallet breach at unnamed exchange partner

Another recent security incident affecting tech platforms

ℹ️

Need Help Implementing This?

If your organization needs to evaluate AI vendor security practices or establish breach response protocols, contact Logicity for consulting recommendations tailored to tech decision-makers.

Source: TechCrunch / Zack Whittaker

H

Huma Shazia

Senior AI & Tech Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.

Related Articles