Suno’s 55M-User Breach

Suno’s 55M-User Breach

If you’ve used Suno, the AI music generator that turns text prompts into songs, now’s the time to check your inbox—not for a notification from them, but for a breach alert.

Here’s the short version: 55.3 million user accounts were exposed in a November 2025 cyberattack. The breach only came to light this month, first reported by 404 Media, and was officially added to Have I Been Pwned on July 20.

What Actually Got Stolen

The leaked data includes names, physical addresses, email addresses, phone numbers, purchase history, and partial payment card details (card type, expiration date, and last four digits) from Suno’s Stripe payment processor. That’s not nothing—even without full card numbers, it’s enough for targeted phishing or identity fraud.

Suno told Have I Been Pwned it “does not have access to customers’ full credit card numbers in Stripe”. Small comfort, but worth noting.

The Source Code Spilled the Real Tea

The hacker didn’t just walk away with user data. They also grabbed Suno’s source code from 2023–2024, which revealed exactly how the company built its AI.

The code shows Suno scraped music and lyrics from:
  • YouTube Music (113,879+ hours, over 2 million clips)
  • Genius (17,615+ hours)
  • Deezer (12,287+ hours)
  • Plus stock libraries like Pond5, Jamendo, Freesound, and IMSLP
One file even shows Suno searched YouTube for a cappella versions to isolate vocals. The company routed scraping through a proxy firm called Bright Data to bypass YouTube’s defenses.

Suno has long admitted training on “publicly available music files” and argued fair use. But the leaked code confirms what the RIAA has been alleging in court: systematic stream-ripping at an industrial scale.

Suno’s Response: “Nothing to See Here”

Suno acknowledged the security incident happened in November 2025 and said it was “quickly contained”. Their official line: the breach primarily exposed “outdated source code that is no longer in use” and no sensitive personal information was compromised.

The 55.3 million email addresses, names, and partial payment data say otherwise.

Even more concerning: Suno never notified affected users. Some victims only found out when 404 Media contacted them to confirm their data was real.

What You Should Do

If you have a Suno account:
  1. Check Have I Been Pwned to see if your email was in the dump.
  2. Change your Suno password—and anywhere you reused it.
  3. Enable two-factor authentication where available.
  4. Watch for phishing attempts—scammers now have your email, name, and address.

The Bigger Picture

This breach isn’t just about 55 million people’s data. It’s a rare window into how AI music companies actually source their training data—and the legal trouble that comes with it.

Sony and Universal are still suing Suno over copyright infringement. Warner settled and struck a partnership instead. The fair use battle is far from over, and this leaked code just handed the plaintiffs a smoking gun.

The takeaway? Whether you care about the copyright fight or just want to keep your personal info safe, this one’s worth paying attention to. Suno’s silence for eight months speaks volumes.

إرسال تعليق

أحدث أقدم