A cyberattack at AI music generator Suno last year allowed a hacker to steal the personal information of more than 55.3 million people, according to the data breach notification service Have I Been Pwned, offering the first glimpse into the scale of the data theft.
Per Have I Been Pwned, which obtained a copy of the breached dataset, the stolen data included customers’ names, physical addresses and email addresses, phone numbers, purchases, and partial payment card numbers taken from the company’s Stripe account, including card expiry dates. The breach happened in November 2025, but was only recently revealed thanks to reporting by independent news outlet 404 Media.
What was stolen?
The compromised data set is one of the largest in the AI sector this year. In addition to user PII, the hacker also exfiltrated Suno’s proprietary source code, which included internal documentation, training pipelines, and scraping infrastructure. According to security researchers, the source code revealed that Suno had systematically scraped millions of songs and lyrics from popular streaming sites, including Deezer, Genius, and YouTube, to train its generative music AI models. This practice is at the heart of a major copyright lawsuit filed against Suno by several major record labels in 2025.
Record labels, including Universal Music Group, Sony Music Entertainment, and Warner Music Group, have accused Suno of widespread copyright infringement by using scraped copyrighted content without permission. The leaked code provides direct evidence of the company’s scraping methods, potentially strengthening the plaintiffs’ case. Industry analysts note that if the court finds Suno liable, it could force a major restructuring of how AI music companies train their models, possibly requiring licensing deals similar to those used by Spotify or Apple Music.
Suno’s response (or lack thereof)
Suno has not yet publicly disclosed the cyberattack, or notified individuals that their information was taken. Suno co-founder Mikey Shulman did not respond to TechCrunch’s request for comment about the incident. After publication, Suno spokesperson Rachel Racusen did not dispute the number of users affected, and confirmed that the company experienced a security incident in November 2025. It’s not clear why the company has not yet publicly acknowledged the data breach on its website. Nor did the company provide TechCrunch, when asked, with any communication the company may have sent to users informing them of a data breach.
This silence is a significant red flag for user trust. Data breach disclosure laws vary by jurisdiction, but many U.S. states and international regulations (like GDPR) require companies to notify affected individuals within a reasonable timeframe—usually 30-60 days. Failure to do so can result in hefty fines and class-action lawsuits. Cybersecurity experts point out that Suno’s inaction may exacerbate the fallout, especially given that payment card numbers, even if partial, can be used in fraud attacks.
Scale of the incident
Have I Been Pwned founder Troy Hunt confirmed that the dataset was legitimate, with email addresses matching known users. He added that the count of 55.3 million unique users aligns with Suno’s reported user base. For context, Suno launched in 2023 and quickly gained popularity, allowing users to generate song lyrics, melodies, and entire tracks using AI prompts. By early 2025, the platform had tens of millions of monthly active users and a freemium model that collected payment details even from some free-tier users (for verification purposes).
The breach is a stark reminder that AI startups often prioritize speed over security. Many companies in the generative AI space operate with lean security teams, using third-party payment processors like Stripe but failing to properly encrypt stored data. In Suno’s case, the stolen data from Stripe included partial credit card numbers—information that, when combined with other public records, can enable identity theft and financial fraud.
Broader implications for the AI industry
The Suno breach is part of a worrying trend. In the past 18 months, several AI companies have suffered major data leaks, including OpenAI’s ChatGPT bug that exposed chat histories, and Hugging Face’s API key compromise. The sector has become a prime target for attackers because of the valuable data they hold: user credentials, proprietary training data, and source code for cutting-edge models. A single breach can harm millions of users and undermine public confidence in AI products.
Regulators are increasingly scrutinizing AI companies’ security practices. The U.S. Federal Trade Commission has hinted at updating data security guidelines specifically for AI firms, while the European Union’s AI Act includes provisions for data governance and risk management. If Suno is found to have been negligent—for instance, by not encrypting user data or by storing sensitive keys in plaintext—it could face severe penalties.
What users should do
Individuals who have used Suno should assume their email, name, address, and partial payment card details are now public. Security experts recommend changing passwords if you used the same credentials elsewhere, enabling two-factor authentication, and monitoring bank statements for unauthorized transactions. Since the breach included phone numbers, users should also be wary of targeted phishing calls or SMS messages claiming to be from Suno or Stripe.
Have I Been Pwned has already added the Suno dataset to its database, allowing users to check if their email was affected.
The road ahead
With a copyright trial looming and now a massive data breach, Suno is facing an existential crisis. The company might consider acquiring cyber insurance, but given the scale of the incident, premiums will be high. The CEO and board must quickly decide how to communicate with regulators, impacted users, and the public. Transparency is key: admitting fault early, offering credit monitoring, and fixing security vulnerabilities could mitigate some long-term damage.
Meanwhile, the leaked source code will likely become a focal point in future AI regulation debates. Policymakers may argue that if a company can’t protect the very code that powers its product, it should not be trusted with users’ data. The Suno breach is a cautionary tale: even the most innovative AI startups are not immune to cyberattacks, and the consequences can reverberate far beyond the immediate financial loss.
Source: TechCrunch News