
AI music generation platform Suno suffered a data breach that exposed the personal information of more than 55 million users, according to Have I Been Pwned (HIBP).
The incident exposed phone numbers and tens of thousands of Stripe purchase records containing customer names, physical addresses, purchase amounts, and partial payment card details.
The breach occurred in November 2025 but only became public last week. While HIBP entries do not constitute official confirmation from the affected company, the service verifies breach datasets before adding them to the platform, providing a high degree of confidence that the exposed data is authentic and originates from the claimed source.
According to HIBP, the breach affected approximately 55.3 million accounts and included email addresses, names, phone numbers, physical addresses, purchase information, and partial credit card data (card type, expiration date, and last four digits) for some customers.
Founded in 2023, Suno is one of the most widely used AI music generation platforms, allowing users to create songs from text prompts. The company has rapidly grown alongside the generative AI boom but has also faced multiple copyright lawsuits from major record labels over allegations that its models were trained on copyrighted music without authorization.
Reports on stolen source code
404 Media reported last week that a hacker had breached Suno and obtained internal source code, along with customer information.
The attacker, who identified themselves as “ellie.191,” claimed to have compromised a Suno employee through the Shai-Hulud worm, a supply chain attack that harvested GitHub and cloud service credentials. The hacker told 404 Media they subsequently gained access to Suno's source code repositories, internal datasets, and customer records.
Beyond user information, the stolen source code reportedly revealed details about how Suno assembled training datasets for its AI models. Files examined by 404 Media allegedly referenced large-scale ingestion of music and audio from sources including YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, the International Music Score Library Project (IMSLP), and podcast RSS feeds.
The leaked code reportedly documented millions of YouTube Music clips and hundreds of thousands of hours of audio collected from various services, offering an unusually detailed look at the datasets used to train commercial AI music generation models.
Suno describes incident as “limited”
In a statement provided to 404 Media, Suno said it detected the security incident in November 2025 and contained it quickly.
The company stated that its investigation concluded the breach primarily involved outdated source code that is no longer used and that “no sensitive personal information was compromised.” Suno also reiterated that it does not store customers' complete payment card numbers through Stripe.
The company further said it determined that individual breach notifications were not required under applicable privacy laws due to the limited customer information believed to have been involved.
However, the newly published HIBP listing indicates that the dataset contains more than 55 million unique email addresses, phone numbers used for account registration, and tens of thousands of Stripe purchase records containing personally identifiable information.
Suno has not publicly acknowledged the full scale of the customer data exposure reflected in the HIBP dataset at the time of writing.
Although the breach does not appear to include passwords or complete payment card numbers, the exposed information could still be valuable to cybercriminals for phishing attacks, account impersonation, and social engineering.
Affected users should remain cautious of unsolicited emails, phone calls, or text messages that claim to be from Suno or payment providers. Those who made purchases through the platform should also monitor their payment accounts for unexpected activity, even though only partial card information was reportedly exposed.






Leave a Reply