Suno Data Breach Affecting 55 Million Users Comes to Light, Leaked Source Code Suggests Unlicensed Scraping of YouTube and Other Sites
A cyberattack on AI music generator Suno that took place in November 2025 has come to light through July 2026 media reporting. Data breach notification service Have I Been Pwned puts the number of affected people at more than 55.3 million.
Details
- Timeline: The breach occurred in November 2025, but Suno had not previously disclosed it publicly; it surfaced through reporting by outlets including 404 Media in July 2026
- Number affected: Over 55.3 million people, according to Have I Been Pwned’s tally
- Data exposed: Names, addresses, email addresses, phone numbers, purchase history, and partial payment card data (including expiry dates) processed via Stripe
- Source code fallout: The stolen data reportedly included Suno’s source code, which pointed to the company allegedly scraping millions of songs and lyrics without authorization from platforms including Deezer, Genius, and YouTube to train its AI models
- Suno’s response: Speaking to TechCrunch, Suno spokesperson Rachel Racusen did not dispute the number of affected users and confirmed the company experienced a security incident in November 2025. However, no evidence of user notifications was provided, and no official public statement or blog post from Suno has been identified as of this writing
- Context: The disclosure comes as Suno faces ongoing copyright litigation from major record labels and a music-industry push for an AI-generated-music labeling system, adding to scrutiny over the provenance of its training data
How to try it
- This is a security incident report, not a product announcement. No detailed official explanation or user notification content from Suno has been confirmed as of this writing
- Suno users are advised to take standard precautions such as changing passwords and reviewing payment information on file
- Check Suno’s official site (suno.com) for any follow-up statement