Suno: 55M Users Exposed in Massive Data Breach
A security expert reveals that the AI music platform suffered a breach compromising emails, phone numbers, and partial financial data, and also exposed code that would prove mass scraping.
July 22, 2026 · 3 min read
TL;DR: The AI music platform Suno suffered a breach affecting 55 million users, exposing emails, phones, and partial financial data. The attacker also leaked code that would show scraping of YouTube Music and Deezer. Suno faces copyright infringement lawsuits.
What Happened?
The AI-generated music platform Suno has been hit by a massive data breach exposing over 55 million user accounts. The breach was confirmed by Troy Hunt, founder of Have I Been Pwned (HIBP), who integrated the leaked files into his notification service. The compromised data primarily includes email addresses, but also phone numbers of users who opted to register with them. More worryingly, tens of thousands of Stripe records revealed full names, physical addresses, purchase amounts, and partial credit card data: card type, expiration date, and last four digits.
The Context: Scraping and Lawsuits
This breach is not an isolated incident. Suno was already under scrutiny for its AI training practices. The individual claiming responsibility for the breach also leaked source code from 2023 and 2024 that, according to them, proves the company scraped millions of songs and lyrics from services like YouTube Music, Deezer, and Genius to train its models. Suno has publicly acknowledged using music available on the open internet, arguing this constitutes fair use. However, this stance has led to lawsuits from major record labels. In 2024, the Recording Industry Association of America (RIAA) filed a class-action lawsuit against Suno and its rival Udio for alleged copyright infringement. Plaintiffs include Sony Music Entertainment, UMG Recordings, and Warner Records, representing artists like Bruce Springsteen, Beyoncé, Taylor Swift, and Dua Lipa. Notably, Warner reached an out-of-court settlement with Suno and has initiated a business partnership, while Sony and UMG continue litigation.
Impact and Consequences
The scale of the breach —55 million accounts— puts Suno on the radar of data protection regulators, especially in the European Union under GDPR, which can impose fines of up to 4% of global annual revenue. Moreover, the exposure of financial data, albeit partial, increases the risk of fraud and targeted phishing. For users, this means being alert to suspicious emails or messages impersonating Suno. Reputationally, the breach deepens distrust toward generative AI platforms, which already face criticism for unauthorized use of copyrighted content. The leaked code could be used in court as evidence of deliberate infringement, strengthening the plaintiffs' position.
What Should Readers Know?
If you are a Suno user, first check if your email appears in the breach via Have I Been Pwned. Change your password immediately, and if you use the same one elsewhere, change it there too. Review your bank and credit card statements for unauthorized charges. Enable two-factor authentication if available. Also, be skeptical of any communication requesting personal or financial information, even if it appears to be from Suno. For the general public, this case underscores the risks of sharing data with emerging platforms and the importance of companies implementing robust security measures from the start.
“The combination of a massive data breach with the exposure of questionable scraping practices creates a perfect storm for Suno, which now faces not only regulatory scrutiny but also significant reputational damage,” notes TheVortiq analyst.
Lessons for the Industry
The Suno incident is a reminder that AI innovation cannot come at the expense of security and ethics. Companies must prioritize data protection by design and be transparent about their training sources. The breach also highlights the need for clearer regulation on data scraping and the use of copyrighted content. While courts decide on these issues, users and companies should act with caution.