All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
The personal info of around 55 million users was exposed in a data breach that Suno suffered in November 2025,[1] but the AI song generator app didn't notify users of the incident. It only came to light in July 2026 when 404 Media published a report[2] based on information shared by the hacker ellie.191.
This means if you've ever signed up using your email or phone number to use the popular AI music generation platform, your details could now be out there in the wild.
In the wrong hands, this personally identifiable information can be used to launch highly targeted phishing attacks against you or commit identity theft and financial fraud.
Here's everything that went down in the Suno data breach and the steps you can take now to protect your privacy.
Suno's disputed use of copyrighted music
What can you do to protect yourself
Bottom line
What Suno didn't tell you
According to 404 Media’s report, the hacker breached the company by gaining access to an employee's account using the Shai-Hulud worm, a supply-chain worm that steals cloud service and GitHub login credentials.
In addition to not acknowledging the data breach or notifying its users, Suno continued to downplay the incident even after it became public. A Suno spokesperson told 404 Media that no sensitive personal information had been compromised and that only outdated source code had been breached during the attack.
Moreover, since the nature of the customer information was fairly limited, Suno believed that individual notifications were not required under applicable privacy laws. We saw a similarly low level of accountability in the recent Puerto Rico data breach.
However, Have I Been Pwned (HIBP)'s analysis of the shared source code and dataset contradicts this statement. The site has confirmed that the following details were leaked during the data breach:
- 55 million unique email addresses
- Phone numbers (if they had been used for signing up)
- Tens of thousands of Stripe records containing information such as names, addresses, purchase amounts, and partial credit card data, including card type, expiry date, and the last four digits
Suno's disputed use of copyrighted music
The breach is just one part of the story. The hacker was also able to access Suno's training library, which was shared with 404 Media, revealing that the company had scraped millions of lyrics and songs from platforms such as YouTube Music, Genius, Deezer, as well as other stock music libraries.
Source code from 2023 and 2024 reportedly revealed a file containing comments about various datasets created by Suno. This included the following:
- 113,879 hours of YouTube Music audio
- 17,615 hours of Genius audio
- 410 hours of Freesound
- 19,514 hours of IMSLP
- 3,726 hours of Jamendo
- 62,117 hours of Pond5 music
- 12,287 hours of Deezer
- 152,162 hours of ytm_tagged
- 103 hours of musescore_lyrics
In all, Suno seems to have scraped decades' worth of music and audio.
While it’s still unclear exactly how Suno was able to scrape these files from each platform, the source code revealed that the company had been using proxies through a company called Bright Data to scrape songs from YouTube.
Notably, Suno is facing a lawsuit for the unlicensed use of copyrighted music and songs to train its AI models. The Recording Industry Association of America (RIAA) sued Suno on behalf of Sony Music, Universal Music Group (UMG), and Warner Music Group in Massachusetts in June 2024, seeking statutory damages of up to $150,000 per work.
However, in November 2025, Warner Music Group dropped out of the case in exchange for a licensing partnership. UMG and Sony are still pursuing the case.
As first reported by 404 Media, Suno has acknowledged the use of copyrighted material to train its AI in response to the RIAA case. The company went on to defend the practice by saying it falls under the "fair use" clause of copyright law.
"Suno's training data includes essentially all music files of reasonable quality that are accessible on the open internet, abiding by paywalls, password protections, and the like, combined with similarly available text descriptions," Suno said in its response.
But Suno went a step further, saying that various labels are trying to misuse their exclusive rights to "strong-arm users" and deter them from using artificial intelligence products.
The recent data breach details have only confirmed the extent of the unlicensed material the company used while training its AI, which it now argues falls under "fair use."
This case could be pivotal for the AI industry, with $9 billion in potential damages at stake. If the court agrees with Suno's fair-use claims, it could set a precedent for similar AI companies using copyrighted works.
What can you do to protect yourself
Given Suno's timid response to the data breach, here are a few steps you can take today to reclaim your digital privacy and keep your accounts secure.
- Check if you're affected: Visit Have I Been Pwned's website and enter your email address to check whether you were part of the Suno data breach. The website will also list all previous breaches your email has been a part of. According to HIBP, around 24% of the email addresses leaked in the Suno breach had already appeared in previous breaches.
- Change your passwords: If you suspect your privacy has been compromised, change the passwords for your critical accounts, especially if you've reused the same password across multiple accounts. Consider using a password manager to generate unique, strong passwords for each account and store them securely for you.
- Watch out for phishing attempts: Avoid clicking on any suspicious links in messages claiming to be from Suno or any other service, as attackers may use your leaked email address or phone number to send fake security alerts or billing notices.
- Monitor your bank and card statements: Because the exposed Stripe-related payment information could be used for financial fraud, look out for any unfamiliar test charges, which are a common tactic fraudsters use to confirm whether transactions are going through. In addition to regularly monitoring your accounts, consider placing credit freezes and fraud alerts.
- Use an identity theft protection service: These services continuously monitor leaked databases, breach dumps, and dark web marketplaces for your personal information and alert you if your data turns up somewhere new.
Bottom line
Where most organizations acknowledge data breaches and work on improving their security practices, Suno's lack of response and assistance to users after sensitive information such as email addresses, phone numbers, and even payment-related data was leaked is unfortunate.
To ensure that the stolen information isn't misused for identity theft or further scams, first confirm whether your email has been breached using Have I Been Pwned's service.
Other proactive steps you can take include staying cautious of phishing links, changing reused passwords, and using third-party protection tools such as identity theft protection services and credit freezes.
[1] Suno Data Breach (Have I Been Pwned)
[2] Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius