Suno AI Music Platform Suffers Massive Data Breach, Exposing 55.3 Million Records
In November 2025, AI music generator Suno fell victim to a cyberattack that resulted in the theft of personal data belonging to over 55.3 million users, a breach only revealed this week by breach notification service Have I Been Pwned. The stolen dataset includes names, physical and email addresses, phone numbers, purchase records, and partial payment card details including card types, expiry dates, and the last four digits linked to Suno’s Stripe account.
Beyond customer data, the hacker also exfiltrated Suno’s source code, which reportedly documents how the company scraped songs and lyrics from platforms like Deezer, Genius, and YouTube to train its AI models. This revelation could significantly impact ongoing copyright lawsuits filed by major record labels in 2024, which allege Suno violated copyright law by using unlicensed music for training. The leaked code may serve as evidence in the litigation, where labels are seeking up to $150,000 per song for 662 allegedly copied tracks.
Despite the breach’s severity, Suno has not publicly disclosed the incident or notified affected users. A spokesperson confirmed the November 2025 security incident but did not explain the delay in communication. Such prolonged silence may draw regulatory scrutiny, as breach notification laws in the EU, UK, and U.S. states typically require disclosure within days.
The attack reportedly stemmed from stolen employee credentials rather than a direct system compromise. While Suno has stated it does not store full credit card numbers, the exposed partial payment details combined with personal information could facilitate social engineering attacks, such as fraudulent calls impersonating banks.
The breach adds to Suno’s legal and reputational challenges, as the company continues to defend its fair use argument in court. Competitors, meanwhile, have taken a different approach, licensing music data and offering enterprise indemnification to avoid similar legal risks.
Source: https://www.technology.org/2026/07/23/suno-data-breach-55-million-users/
Deezer TPRM report: https://www.rankiteo.com/company/deezer
Suno TPRM report: https://www.rankiteo.com/company/sunomusic
Genius TPRM report: https://www.rankiteo.com/company/genius-group-ltd
"id": "deesungen1784831487",
"linkid": "deezer, sunomusic, genius-group-ltd",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': '55.3 million',
'industry': 'AI Music Generation',
'name': 'Suno',
'type': 'Company'}],
'attack_vector': 'Stolen employee credentials',
'data_breach': {'data_exfiltration': 'Yes',
'file_types_exposed': ['Source code', 'User data'],
'number_of_records_exposed': '55.3 million',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Physical addresses',
'Email addresses',
'Phone numbers',
'Purchase records',
'Partial payment card details '
'(card types, expiry dates, last '
'four digits)',
'Source code']},
'date_detected': '2025-11',
'description': 'AI music generator Suno suffered a cyberattack in November '
'2025, resulting in the theft of personal data belonging to '
'over 55.3 million users. The breach exposed names, physical '
'and email addresses, phone numbers, purchase records, and '
'partial payment card details. Additionally, Suno’s source '
'code was exfiltrated, revealing how the company scraped songs '
'and lyrics from platforms like Deezer, Genius, and YouTube to '
'train its AI models. The breach was only publicly disclosed '
'this week by breach notification service Have I Been Pwned.',
'impact': {'brand_reputation_impact': 'Significant',
'data_compromised': '55.3 million records',
'identity_theft_risk': 'High (social engineering attacks)',
'legal_liabilities': 'Potential regulatory fines and copyright '
'lawsuit damages',
'payment_information_risk': 'Partial payment card details exposed'},
'initial_access_broker': {'entry_point': 'Stolen employee credentials'},
'post_incident_analysis': {'root_causes': 'Stolen employee credentials'},
'references': [{'source': 'Have I Been Pwned'}],
'regulatory_compliance': {'legal_actions': 'Ongoing copyright lawsuits '
'(potential regulatory actions)',
'regulations_violated': ['EU GDPR',
'UK Data Protection Act',
'U.S. state breach '
'notification laws']},
'response': {'communication_strategy': 'No public disclosure or user '
'notifications'},
'title': 'Suno AI Music Platform Data Breach',
'type': 'Data Breach'}