In one of the largest data breaches affecting the AI music generation sector, Suno, a popular platform that uses artificial intelligence to create music, has suffered a cyberattack that compromised the personal information of more than 55.3 million users. The breach was first reported by the data breach notification service Have I Been Pwned, which obtained a copy of the stolen dataset and provided the first concrete insight into the scale of the theft.
The incident occurred in November 2025, but only recently came to light through reporting by independent news outlet 404 Media. According to Have I Been Pwned, the stolen data includes a wide range of sensitive customer information: names, physical addresses, email addresses, phone numbers, purchase histories, and partial payment card numbers taken from Suno’s Stripe account, including card expiration dates. The inclusion of financial data makes this breach particularly concerning for affected users, as it exposes them to potential fraud and identity theft.
Beyond the customer data, the attackers also gained access to Suno’s proprietary source code. Analysis of the stolen code revealed evidence that Suno had scraped millions of songs and lyrics from popular streaming and music platforms, including Deezer, Genius, and YouTube, to train its AI models. This revelation adds a new dimension to the ongoing legal battles Suno faces. Several major record labels have filed lawsuits against Suno, alleging that its mass‑scraping efforts violate copyright law. The breach provides plaintiffs with concrete evidence of the company’s data‑collection practices.
Despite the severity of the breach, Suno has not yet publicly disclosed the cyberattack or notified affected individuals that their information was stolen. TechCrunch reached out to Suno co‑founder Mikey Shulman for comment but did not receive a response. However, after publication, Suno spokesperson Rachel Racusen did not dispute the number of users affected and confirmed that the company experienced a security incident in November 2025. The spokesperson did not explain why Suno has not publicly acknowledged the breach on its website or sent any communication to users informing them of the data theft.
What the Stolen Data Means for Users
For the 55.3 million affected individuals, the exposure of personal identifiers such as names, addresses, and phone numbers can lead to an increased risk of phishing attacks, spam, and identity theft. The inclusion of partial payment card numbers, even without full card details, is valuable for cybercriminals who can combine them with other data obtained from separate breaches to perpetrate fraud. The presence of purchase histories also gives attackers insight into users’ behaviors, which can be exploited in targeted scams.
Have I Been Pwned founder Troy Hunt noted that the dataset appeared to be comprehensive, including records dating back several years. He urged users to be vigilant and monitor their financial accounts for suspicious activity. The breach is particularly troubling because Suno, like many AI startups, likely has a relatively young user base that may be less experienced in managing data‑security risks.
Background on Suno and Its Rise
Suno was founded in 2022 and quickly became one of the most popular AI music generation tools, allowing users to create original songs by providing text prompts. The platform’s technology leverages deep‑learning models trained on vast libraries of music to produce compositions in a wide variety of genres. By 2025, Suno had attracted tens of millions of users globally and had raised significant venture capital funding. The company’s rapid growth, however, has been shadowed by legal controversies over its training data.
The breach reveals that Suno’s training data was sourced from major streaming and lyrics platforms without authorization. This practice is at the heart of the copyright lawsuits filed by record labels such as Universal Music Group, Sony Music Entertainment, and Warner Music Group. The lawsuits argue that Suno’s scraping of copyrighted songs and lyrics to train its AI constitutes massive copyright infringement. The source code leak now gives the plaintiffs direct access to the precise methods and scale of Suno’s scraping activities, potentially strengthening their cases.
The Role of Have I Been Pwned
Have I Been Pwned (HIBP) is a widely respected service that aggregates data from breaches and allows users to check if their email addresses or personal information have been compromised. HIBP obtained the Suno dataset through its network of sources, which often include security researchers and underground forum monitors. By adding the Suno breach to its database, HIBP enables affected users to proactively take steps to protect themselves, such as changing passwords, enabling two‑factor authentication, and freezing credit reports.
Troy Hunt, the founder of HIBP, commented that the Suno breach is one of the largest ever involving an AI company. He stressed that the failure of Suno to notify users promptly is a breach of trust and may violate data protection regulations in various jurisdictions, including the European Union’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
Legal and Regulatory Implications
The Suno breach could trigger investigations by data protection authorities. Under GDPR, companies are required to notify affected individuals and regulators within 72 hours of becoming aware of a breach that poses a risk to users’ rights and freedoms. Suno’s delay in disclosure may result in significant fines. Similarly, in the United States, state attorneys general may investigate potential violations of consumer protection laws.
The simultaneous exposure of copyrighted source code adds another layer of legal exposure. If the stolen code is used by competitors or malicious actors, Suno could face further intellectual property claims. The company may also be liable for damages resulting from the theft of its customers’ financial data.
Lessons for the Tech Industry
The Suno incident underscores the vulnerability of AI startups that often prioritize speed to market over robust security practices. The breach was reportedly enabled by a misconfigured server or a compromised credential, according to initial analyses. This highlights the need for companies handling large volumes of sensitive user data to implement rigorous access controls, regular security audits, and incident response plans.
For the broader AI music industry, the breach serves as a cautionary tale. Many AI music generation tools rely on training data scraped from the internet, often raising legal and ethical questions. The Suno case may accelerate calls for clearer regulations governing the use of copyrighted material in AI training, as well as stricter data protection standards for companies that collect and store user financial information.
As of late January 2026, Suno has not posted a notice on its website or sent any breach notification emails to users, despite having confirmed the incident to reporters. This silence is likely to erode user trust and could lead to a wave of class‑action lawsuits. Affected users are advised to monitor their accounts and consider identity theft protection services. The full impact of the breach may not be known for months, but it has already left a lasting mark on the AI music landscape.
Source: TechCrunch News