Suno’s 2025 Data Breach Exposed 55M Email Addresses, Payment Details, and AI Training Secrets
In November 2025, AI music startup Suno suffered a supply-chain attack that compromised extensive user data and internal systems. The breach, which remained undisclosed for eight months, was confirmed on July 20, 2026, when breach monitoring service Have I Been Pwned listed 55.3 million unique email addresses tied to Suno’s systems.
The attack originated from malware on a developer’s laptop, introduced via third-party code. The threat actor used stolen credentials to move laterally within Suno’s environment, accessing Stripe payment records, source code repositories, and user data. Exposed information included names, physical addresses, phone numbers, purchase histories, and partial payment card numbers with expiry dates. Suno initially downplayed the incident, claiming only "outdated source code" was affected a statement contradicted by TechCrunch and Mozilla Monitor.
Beyond user data, the breach revealed Suno’s AI training pipeline, providing rare evidence for ongoing RIAA lawsuits. Leaked documentation detailed a large-scale scraping operation, including:
- 113,879 hours of YouTube Music content
- 152,162 tagged YouTube tracks
- 62,117 Pond5 files
- 12,287 Deezer tracks
- 17,615 Genius lyrics
- 19,514 IMSLP files
Suno reportedly used Bright Data, a commercial proxy service, to bypass anti-bot protections while harvesting content. The company has previously argued its training practices fall under fair use, but the leaked code provides concrete evidence for copyright disputes.
Despite the severity of the breach, Suno has not notified affected users. Independent services like Have I Been Pwned and Mozilla Monitor remain the primary sources of disclosure for those impacted.
Source: https://tech.yahoo.com/cybersecurity/articles/suno-data-breach-hit-55-182527083.html
Genius Sports cybersecurity rating report: https://www.rankiteo.com/company/geniussports
Stripe cybersecurity rating report: https://www.rankiteo.com/company/stripe
Bright Data cybersecurity rating report: https://www.rankiteo.com/company/bright-data
Suno cybersecurity rating report: https://www.rankiteo.com/company/sunomusic
"id": "GENSTRBRISUN1784666335",
"linkid": "geniussports, stripe, bright-data, sunomusic",
"type": "Breach",
"date": "11/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '55.3 million',
'industry': 'AI Music Startup',
'name': 'Suno',
'type': 'Company'}],
'attack_vector': 'Supply-chain attack (malware on developer’s laptop via '
'third-party code)',
'customer_advisories': 'None issued by Suno; independent services (Have I '
'Been Pwned, Mozilla Monitor) provided disclosure',
'data_breach': {'data_exfiltration': 'Yes (AI training pipeline details, user '
'data)',
'number_of_records_exposed': '55.3 million email addresses',
'personally_identifiable_information': 'Yes (names, '
'addresses, phone '
'numbers, email '
'addresses)',
'sensitivity_of_data': 'High (PII, payment details, '
'proprietary AI training data)',
'type_of_data_compromised': ['Email addresses',
'Names',
'Physical addresses',
'Phone numbers',
'Purchase histories',
'Partial payment card numbers',
'Expiry dates',
'AI training pipeline details',
'Source code']},
'date_detected': '2025-11',
'date_publicly_disclosed': '2026-07-20',
'description': 'In November 2025, AI music startup Suno suffered a '
'supply-chain attack that compromised extensive user data and '
'internal systems. The breach, which remained undisclosed for '
'eight months, was confirmed on July 20, 2026, when breach '
'monitoring service *Have I Been Pwned* listed 55.3 million '
'unique email addresses tied to Suno’s systems. The attack '
'originated from malware on a developer’s laptop, introduced '
'via third-party code. The threat actor used stolen '
'credentials to move laterally within Suno’s environment, '
'accessing Stripe payment records, source code repositories, '
'and user data. Exposed information included names, physical '
'addresses, phone numbers, purchase histories, and partial '
'payment card numbers with expiry dates. Beyond user data, the '
'breach revealed Suno’s AI training pipeline, providing rare '
'evidence for ongoing RIAA lawsuits.',
'impact': {'brand_reputation_impact': 'Significant (downplayed incident, '
'contradicted by third-party reports)',
'data_compromised': '55.3 million unique email addresses, names, '
'physical addresses, phone numbers, purchase '
'histories, partial payment card numbers with '
'expiry dates, AI training pipeline details',
'identity_theft_risk': 'High (PII and payment details exposed)',
'legal_liabilities': 'Potential (RIAA lawsuits, regulatory '
'violations)',
'operational_impact': 'Compromised internal systems, delayed '
'public disclosure, legal and reputational '
'risks',
'payment_information_risk': 'High (partial payment card numbers '
'and expiry dates exposed)',
'systems_affected': 'Stripe payment records, source code '
'repositories, user databases, AI training '
'systems'},
'initial_access_broker': {'entry_point': 'Malware on developer’s laptop via '
'third-party code',
'high_value_targets': 'Stripe payment records, '
'source code repositories, AI '
'training pipeline'},
'investigation_status': 'Ongoing (publicly disclosed but not fully resolved)',
'motivation': 'Data exfiltration, potential financial gain, intellectual '
'property theft',
'post_incident_analysis': {'root_causes': 'Supply-chain attack (third-party '
'code), stolen credentials, lateral '
'movement, lack of timely '
'disclosure'},
'references': [{'date_accessed': '2026-07-20', 'source': 'Have I Been Pwned'},
{'source': 'TechCrunch'},
{'source': 'Mozilla Monitor'}],
'regulatory_compliance': {'legal_actions': 'RIAA lawsuits (ongoing)',
'regulations_violated': ['Potential GDPR (if EU '
'users affected)',
'Potential CCPA (if '
'California users '
'affected)']},
'response': {'communication_strategy': 'Downplayed incident initially, no '
'direct user notifications'},
'title': 'Suno’s 2025 Data Breach Exposed 55M Email Addresses, Payment '
'Details, and AI Training Secrets',
'type': 'Data Breach',
'vulnerability_exploited': 'Stolen credentials, lateral movement'}