Suno’s Data Breach Exposed 55 Million Users' Information, but the AI Song Generator App Didn’t Tell You

Suno didn't disclose its November 2025 data breach for eight months, leaving users vulnerable to identity theft and phishing attacks.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

The personal info of around 55 million users was exposed in a data breach that Suno suffered in November 2025,[1] but the AI song generator app didn't notify users of the incident. It only came to light in July 2026 when 404 Media published a report[2] based on information shared by the hacker ellie.191.

This means if you've ever signed up using your email or phone number to use the popular AI music generation platform, your details could now be out there in the wild.

In the wrong hands, this personally identifiable information can be used to launch highly targeted phishing attacks against you or commit identity theft and financial fraud.

Here's everything that went down in the Suno data breach and the steps you can take now to protect your privacy.

In this article
What Suno didn't tell you
Suno's disputed use of copyrighted music
What can you do to protect yourself
Bottom line

What Suno didn't tell you

According to 404 Media’s report, the hacker breached the company by gaining access to an employee's account using the Shai-Hulud worm, a supply-chain worm that steals cloud service and GitHub login credentials.

In addition to not acknowledging the data breach or notifying its users, Suno continued to downplay the incident even after it became public. A Suno spokesperson told 404 Media that no sensitive personal information had been compromised and that only outdated source code had been breached during the attack.

Moreover, since the nature of the customer information was fairly limited, Suno believed that individual notifications were not required under applicable privacy laws. We saw a similarly low level of accountability in the recent Puerto Rico data breach.

However, Have I Been Pwned (HIBP)'s analysis of the shared source code and dataset contradicts this statement. The site has confirmed that the following details were leaked during the data breach:

  • 55 million unique email addresses
  • Phone numbers (if they had been used for signing up)
  • Tens of thousands of Stripe records containing information such as names, addresses, purchase amounts, and partial credit card data, including card type, expiry date, and the last four digits

Suno's disputed use of copyrighted music

The breach is just one part of the story. The hacker was also able to access Suno's training library, which was shared with 404 Media, revealing that the company had scraped millions of lyrics and songs from platforms such as YouTube Music, Genius, Deezer, as well as other stock music libraries.

Source code from 2023 and 2024 reportedly revealed a file containing comments about various datasets created by Suno. This included the following:

  • 113,879 hours of YouTube Music audio
  • 17,615 hours of Genius audio
  • 410 hours of Freesound
  • 19,514 hours of IMSLP
  • 3,726 hours of Jamendo
  • 62,117 hours of Pond5 music
  • 12,287 hours of Deezer
  • 152,162 hours of ytm_tagged
  • 103 hours of musescore_lyrics

In all, Suno seems to have scraped decades' worth of music and audio.

While it’s still unclear exactly how Suno was able to scrape these files from each platform, the source code revealed that the company had been using proxies through a company called Bright Data to scrape songs from YouTube.

Notably, Suno is facing a lawsuit for the unlicensed use of copyrighted music and songs to train its AI models. The Recording Industry Association of America (RIAA) sued Suno on behalf of Sony Music, Universal Music Group (UMG), and Warner Music Group in Massachusetts in June 2024, seeking statutory damages of up to $150,000 per work.

However, in November 2025, Warner Music Group dropped out of the case in exchange for a licensing partnership. UMG and Sony are still pursuing the case.

As first reported by 404 Media, Suno has acknowledged the use of copyrighted material to train its AI in response to the RIAA case. The company went on to defend the practice by saying it falls under the "fair use" clause of copyright law.

"Suno's training data includes essentially all music files of reasonable quality that are accessible on the open internet, abiding by paywalls, password protections, and the like, combined with similarly available text descriptions," Suno said in its response.

But Suno went a step further, saying that various labels are trying to misuse their exclusive rights to "strong-arm users" and deter them from using artificial intelligence products.

The recent data breach details have only confirmed the extent of the unlicensed material the company used while training its AI, which it now argues falls under "fair use."

This case could be pivotal for the AI industry, with $9 billion in potential damages at stake. If the court agrees with Suno's fair-use claims, it could set a precedent for similar AI companies using copyrighted works.

What can you do to protect yourself

Given Suno's timid response to the data breach, here are a few steps you can take today to reclaim your digital privacy and keep your accounts secure.

  1. Check if you're affected: Visit Have I Been Pwned's website and enter your email address to check whether you were part of the Suno data breach. The website will also list all previous breaches your email has been a part of. According to HIBP, around 24% of the email addresses leaked in the Suno breach had already appeared in previous breaches.
  2. Change your passwords: If you suspect your privacy has been compromised, change the passwords for your critical accounts, especially if you've reused the same password across multiple accounts. Consider using a password manager to generate unique, strong passwords for each account and store them securely for you.
  3. Watch out for phishing attempts: Avoid clicking on any suspicious links in messages claiming to be from Suno or any other service, as attackers may use your leaked email address or phone number to send fake security alerts or billing notices.
  4. Monitor your bank and card statements: Because the exposed Stripe-related payment information could be used for financial fraud, look out for any unfamiliar test charges, which are a common tactic fraudsters use to confirm whether transactions are going through. In addition to regularly monitoring your accounts, consider placing credit freezes and fraud alerts.
  5. Use an identity theft protection service: These services continuously monitor leaked databases, breach dumps, and dark web marketplaces for your personal information and alert you if your data turns up somewhere new.

Bottom line

Where most organizations acknowledge data breaches and work on improving their security practices, Suno's lack of response and assistance to users after sensitive information such as email addresses, phone numbers, and even payment-related data was leaked is unfortunate.

To ensure that the stolen information isn't misused for identity theft or further scams, first confirm whether your email has been breached using Have I Been Pwned's service.

Other proactive steps you can take include staying cautious of phishing links, changing reused passwords, and using third-party protection tools such as identity theft protection services and credit freezes.

4.8
Editorial Rating
Get Deal
On DeleteMe's website
2026 Editors’ Choice
Best Data Removal for Couples
Privacy Protection
DeleteMe
PROMOTION: Use the Code PARTNER20 for 20% Off
  • Data removal service that covers 85-262 sites and re-scans every quarter to catch anything that reappears
  • Sends quarterly privacy reports showing what info was found, which brokers had your data, and how long each removal took
  • Includes email masking so you can share a stand-in address instead of your real one

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Suno Data Breach (Have I Been Pwned)

[2] Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius