BIP Illinois News

collapse
Home / Daily News Analysis / AI music generator Suno breach affects 55M users, per Have I Been Pwned

AI music generator Suno breach affects 55M users, per Have I Been Pwned

Jul 22, 2026  Twila Rosenbaum  8 views
AI music generator Suno breach affects 55M users, per Have I Been Pwned

AI music generator Suno has been hit by a massive data breach that affected more than 55.3 million users, according to data breach notification service Have I Been Pwned. The breach, which occurred in November 2025, was only recently brought to light through reporting by independent news outlet 404 Media.

Have I Been Pwned, which obtained a copy of the breached dataset, revealed that the stolen data includes customers' names, physical addresses, email addresses, phone numbers, purchase histories, and partial payment card numbers taken from Suno's Stripe account, including card expiry dates. The dataset did not include full credit card numbers, as Stripe typically tokenizes such sensitive data, but the exposed partial details still pose significant privacy and security risks for users.

The scope of the breach

The sheer number of affected individuals—55.3 million—makes this one of the largest data breaches in the AI industry to date. Suno, which allows users to generate music using artificial intelligence from text prompts, has seen rapid growth since its launch. Its user base includes musicians, content creators, and hobbyists who use the platform to create original compositions or remix existing ideas. The breach places this vast community at risk of phishing attacks, identity theft, and financial fraud.

Cybercriminals who obtained the data could use the combination of personal information, such as names and email addresses, to craft highly targeted social engineering campaigns. The inclusion of partial payment card numbers and expiry dates increases the likelihood of card-not-present fraud, even though the full card numbers are missing. Have I Been Pwned founder Troy Hunt noted that the stolen data could also be combined with other breached datasets to build more complete profiles of individuals.

Source code leak and copyright controversy

Beyond user data, the attackers also stole Suno's source code. The leaked code allegedly revealed how the company scraped millions of songs and lyrics from popular streaming services, including Deezer, Genius, and YouTube, to train its AI models. This discovery has added fuel to an ongoing legal battle between Suno and several major record labels, who are suing the company for copyright infringement. The labels claim that Suno's mass-scraping efforts violate copyright law by using copyrighted material without permission to train its algorithms.

The source code leak provides public evidence of the alleged scraping practices, which could complicate Suno's defense in court. Record labels, including Universal Music Group, Sony Music Entertainment, and Warner Music Group, have been increasingly aggressive in pursuing legal action against AI companies that use their intellectual property without licenses. The leak may also prompt regulatory scrutiny from data protection authorities, as scraping personal data without consent could violate privacy laws like the GDPR and CCPA.

Company response

Suno has not yet publicly disclosed the cyberattack or notified individuals that their information was taken. When contacted by TechCrunch, Suno co-founder Mikey Shulman did not respond to a request for comment. However, after publication, Suno spokesperson Rachel Racusen did not dispute the number of users affected and confirmed that the company experienced a security incident in November 2025.

It remains unclear why the company has not publicly acknowledged the data breach on its website. Data breach notification laws in many jurisdictions require companies to inform affected users and regulators within a reasonable timeframe. For example, under California's CCPA and the EU's GDPR, companies must notify individuals without undue delay if their personal data is compromised. Suno's silence raises questions about its compliance with these regulations, especially given the large number of affected users worldwide.

The company also did not provide any communication it may have sent to users informing them of the data breach. Often, companies offer credit monitoring or identity theft protection services to affected individuals, but Suno has not announced any such measures. This lack of transparency could damage user trust and lead to class-action lawsuits.

Implications for the AI industry

The Suno breach serves as a stark reminder of the cybersecurity challenges facing the rapidly growing AI sector. Many AI startups prioritize product development and user growth over security, leaving sensitive data vulnerable. The incident also highlights the interconnected nature of data and intellectual property theft—the same attackers who stole source code also accessed user payment information.

Security experts have long warned that AI companies are prime targets for cybercriminals due to their vast collections of user data and proprietary algorithms. The breach of Suno's source code could have additional repercussions: competitors or malicious actors could analyze the code to find vulnerabilities, replicate scraping methodologies, or even modify the software for malicious purposes.

What users should do

Users who have accounts with Suno should take immediate precautions. First, change passwords on the platform and any other services that share the same credential. Enable two-factor authentication if available. Monitor bank and credit card statements for unauthorized transactions, especially those involving small test charges that criminals often use before larger fraud. Consider placing a fraud alert or credit freeze with major credit bureaus to prevent new accounts from being opened in your name.

Have I Been Pwned allows users to check if their email addresses appear in the breached dataset. The service has already added Suno to its database, so individuals can visit the site and search for their email. If their data is exposed, they should be extra vigilant against phishing attempts that may reference the breach.

Technical details of the attack

While the full details of how the attackers gained access have not been disclosed, incident response experts suspect it may have involved an unsecured cloud storage bucket, compromised credentials, or a vulnerability in Suno's infrastructure. The theft of both user data and source code suggests that the attackers had extensive access to Suno's internal systems. Security researchers are likely analyzing the leaked data to identify the attack vector and help prevent similar incidents in the future.

The breach also raises questions about Suno's data retention practices. Storing partial payment card data, even in tokenized form, requires strict security measures. Companies that process payments typically adhere to the Payment Card Industry Data Security Standard (PCI DSS), which mandates encryption, access controls, and regular security audits. The exposure of this data indicates that Suno may not have fully complied with these standards, potentially exposing the company to further legal and financial penalties.

Historical context

Suno is not the only AI company to suffer a significant data breach in recent months. In early 2026, Hugging Face confirmed that its internal datasets and credentials were compromised, urging users to take immediate action. Healthcare tech companies have also been targeted, with hackers stealing significant amounts of data from firms relied on by thousands of hospitals and pharmacies. The trend highlights the increasing frequency and severity of cyberattacks against technology platforms that handle sensitive personal information.

The Suno breach specifically underscores the unique risks faced by generative AI companies. These firms often train models on large datasets scraped from the internet, raising copyright issues that can become legal liabilities. When source code is also stolen, it provides a window into the company's proprietary methods and can be used to reverse-engineer or clone the product. This dual threat—data exposure and intellectual property theft—makes such breaches particularly devastating.

As the investigation continues, affected users are left waiting for official notification from Suno. The company's delay in disclosure could have regulatory consequences, but it also erodes the trust that is essential for any platform that hosts user-generated content. Suno's future may depend on how transparently it handles this crisis and whether it takes meaningful steps to secure its systems and compensate those affected.


Source: TechCrunch News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy