Suno Confirms Breach That Reportedly Impacted 55.3 Million Users

A dataset from the Suno data breach contained more than 55 million unique email addresses, as well as “tens of thousands” of purchase records from Stripe.

Suno
Suno(Credit: Supplied)

Last week, it was reported that the artificial intelligence music creation platform Suno had recently been hacked. Now, the company has confirmed the extent of the data breach.

Music Business Worldwide reports that the data breach occurred in November 2025, reportedly leading to hackers gaining the personal information of 55.3 million users.

Breach notification service Have I Been Pwned began reporting the scale of the hack this week (20 July), revealing that it had obtained a copy of the breached dataset from Suno.

The dataset obtained by Have I Been Pwned held more than 55 million unique email addresses, as well as phone numbers provided by users at sign-up. The dataset also contained “tens of thousands” of purchase records from the service Stripe, which featured users’ names, physical addresses, purchases, and partial card details.

TechCrunch reports that a spokesperson for the company, Rachel Racusen, “did not dispute” the number of users affected by the breach, admitting that the security incident happened last November.

However, when the incident initially occurred, Suno said that it faced “a limited security incident that was quickly contained,” while the incident itself “primarily involved outdated source code that is no longer in use at Suno and that no sensitive personal information was compromised.”

The hack also found that Suno scraped the likes of Deezer, YouTube Music, and other streaming services to train its AI models, The Music’s Tyler Jenke reported last week.

404 Media stated that they received the information about the music creation platform from the hacker in question who “breached the company and shared data about Suno’s training libraries” with the publication.

The data provided to 404 Media includes source code dating back to around “2023 and 2024” and features both instructions and details about the content that was scraped.

The details outline that the likes of YouTube Music, Deezer, and Genius were scraped, as was stock music from libraries such as Pond5, Jamendo, Freesound, and the International Music Score Library Project. Several podcasts were also scraped via numerous RSS feeds.

According to the code, approximately “2,013,545 music clips” had been scraped from YouTube Music, while another file states this amounts to roughly 113,879 hours of material.

That same file also reports data that features “17,615 hours of genius_hq,” “410 hours of free sound,” “19,514 hours of imslp,” “3,726 hours of jamendo,” “62,117 hours of pond5_music,” “12,287 hours of deezer,” “152,162 hours of ytm_tagged,” and “103 hours of musescore_lyrics.”

The hacker in question told 404 Media they had no specific goal or intention for the hack, simply stating they “like to hack anything and everything.”

News of the data scraping and hack arrived just weeks after it was revealed that thousands of songs by Australian artists were among the millions stolen for use in AI datasets.