Security

Suno AI Music Generator Breach Exposed 55M Users' Data

The November 2025 cyberattack stole names, addresses, payment details, and source code revealing alleged mass scraping of copyrighted music.

Omega Editorial· July 21, 2026· 2 min read

Breach scope revealed through third-party service

A cyberattack against AI music generation platform Suno compromised the personal information of more than 55.3 million users, according to data breach notification service Have I Been Pwned. The service obtained a copy of the stolen dataset and confirmed the breach's scale, marking the first public accounting of how many people were affected.

The stolen information included customers' names, physical addresses, email addresses, phone numbers, purchase histories, and partial payment card numbers extracted from Suno's Stripe account. Card expiration dates were also taken in the November 2025 incident.

The breach came to light through reporting by 404 Media, though Suno has not publicly disclosed the cyberattack or notified affected individuals that their data was compromised. Co-founder Mikey Shulman did not respond to requests for comment from TechCrunch, which first reported these details.

Source code theft reveals training practices

Beyond customer data, the attackers also obtained Suno's source code. This code reportedly documented how the company scraped millions of songs and lyrics from major streaming platforms including Deezer, Genius, and YouTube to train its AI models.

The source code disclosure carries particular significance given Suno's ongoing legal battles. Multiple major record labels have filed lawsuits against the company, alleging that its large-scale scraping operations violate copyright law. The stolen code could provide concrete evidence in these cases by revealing the technical methods and scope of Suno's data collection practices.

Why it matters

This breach highlights dual risks facing AI companies that handle user data while operating in legally contested territory. The 55 million affected users face potential identity theft and fraud risks from exposed personal and payment information. Meanwhile, the source code theft could strengthen copyright infringement cases against Suno by documenting alleged unauthorized use of copyrighted material at scale. Companies building AI models on scraped data now face both cybersecurity imperatives and the reality that breaches may expose legally sensitive training methodologies to public scrutiny.

Notification gap raises compliance questions

Months after the November 2025 incident, Suno has not issued public breach notifications. Most data protection regulations, including state laws in the United States and the EU's GDPR, require timely notification when personal information is compromised. The company's silence leaves affected users unable to take protective measures against potential misuse of their stolen data.

The breach details were first reported by TechCrunch's Zack Whittaker, with additional reporting from 404 Media.

#data breach#ai music#suno#copyright#cybersecurity#stripe

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Cisco Releases Antares: Open-Weight AI Models for Code Vulnerability Detection

The 350M and 1B parameter models run locally to pinpoint security flaws in source code without cloud transmission.

Via AI Watch · Jul 21, 2026
Security· 3 min read

ServiceNow AI Platform Flaw Under Active Exploitation

CVE-2026-6875 allows unauthenticated attackers to execute arbitrary code and fully compromise instances.

Via AI Watch · Jul 21, 2026
Security· 2 min read

Chinese Police Built AI Tools to Infiltrate Dark Web Content

Law enforcement researchers developed specialized systems to bypass encryption, collect data, and classify Chinese-language material on anonymous networks.

Via AI Watch · Jul 21, 2026