
A cyberattack on AI music generator Suno last November exposed the personal data of more than 55.3 million users, according to data breach notification service Have I Been Pwned. The breach went undisclosed for months, and Suno still has not publicly acknowledged it on its website.
According to TechCrunch, Have I Been Pwned obtained a copy of the stolen dataset and confirmed the scope of the theft. The stolen data is extensive and includes some sensitive financial details.
Here is what was taken from Suno users:
- Full names and physical addresses
- Email addresses and phone numbers
- Purchase history
- Partial payment card numbers and expiry dates, pulled from the company’s Stripe account
The breach was only brought to light through reporting by independent outlet 404 Media, not through any disclosure by Suno itself. After TechCrunch’s story was published, a Suno spokesperson confirmed the November 2025 incident and did not dispute the number of affected users. Co-founder Mikey Shulman did not respond to requests for comment. The company also did not provide any evidence of breach notifications sent to users.
This silence is a serious problem. Most US states have mandatory data breach notification laws requiring companies to inform affected users within a set window, often 30 to 90 days. A breach of this scale, left unacknowledged for months, raises real questions about Suno’s legal obligations and its relationship with its own user base.
The situation is made worse by what else the hackers got: Suno’s source code. That code apparently revealed how the company scraped millions of songs and lyrics from major streaming platforms, including Deezer, Genius, and YouTube, to train its AI models. Several major record labels are already suing Suno, arguing that this kind of mass scraping breaks copyright law. The stolen source code could become evidence in those legal proceedings.
The broader context here matters. Suno is one of the most popular AI music tools on the market, which is exactly why a breach of this size is so damaging. Users trusted the platform with their payment details and personal information. That trust was broken twice: first by the attacker who got in, and again by a company that chose not to tell anyone.
For anyone who has used Suno, the practical steps right now are straightforward:
- Check Have I Been Pwned to see if your email address appears in the breach
- Monitor your payment card for any unusual activity
- Be alert to phishing attempts, since your name, email, and phone number are now potentially in criminal hands
- Consider using a password manager and enabling two-factor authentication if you haven’t already
Data breaches at AI companies are becoming more common as these platforms scale rapidly and collect large amounts of user data, often without the security infrastructure to match. Suno’s case is a reminder that a flashy product and millions of users does not automatically mean the company behind it is handling your data responsibly.