Suno, Sony Music and UMG Recordings: AI Music Generating Platform Suno Data Breach Affects over 55 Million People

Suno, Sony Music and UMG Recordings: AI Music Generating Platform Suno Data Breach Affects over 55 Million People

Suno AI Music Platform Suffers Massive Data Breach, Exposing 55 Million Users

Suno, a Cambridge, Massachusetts-based AI music generation platform, has confirmed a data breach affecting over 55.3 million users, according to breach tracking site Have I Been Pwned. The incident exposed sensitive user information, including email addresses, phone numbers, and tens of thousands of Stripe payment records containing names, physical addresses, purchase amounts, and partial credit card details (card type, expiry dates, and last four digits). While Suno does not store full credit card numbers, the leaked data could enable targeted phishing attacks, with fraudsters using real transaction details to trick users into disclosing further financial information.

The breach also revealed internal source code from 2023–2024, confirming that Suno trained its AI models using copyrighted music scraped from platforms like YouTube, Deezer, and Genius a practice the company defends as "fair use." This revelation amplifies ongoing legal disputes, including lawsuits from Sony Music, UMG Recordings, and Warner Records, which accuse AI music platforms of mass copyright infringement and undermining human artists. Notably, Warner has since settled with Suno and entered a partnership, while other cases remain unresolved.

Security experts have criticized Suno’s response or lack thereof. The company has not publicly acknowledged the breach, identified the attack vector, or attributed responsibility to a threat actor. Seemant Sehgal, CEO of BreachLock, warned that the scale of the leak suggests poor internal visibility and incident readiness, raising concerns about regulatory scrutiny and customer trust. Meanwhile, Steven Swift of Suzu Labs noted that while AI-assisted development may introduce security risks, most breaches stem from failure to follow basic security practices, emphasizing the need for regular penetration testing and robust controls.

The incident underscores broader tensions in the AI music industry, where platforms like Suno, Udio, and Stability AI face accusations of enabling deepfake music replicating artists’ voices and styles to create near-identical imitations of hits, including songs like Mariah Carey’s "All I Want for Christmas Is You." Critics argue these tools risk devaluing human creativity and facilitating fraud, while proponents claim they democratize music production. For now, the fallout from Suno’s breach remains unresolved, with affected users at heightened risk of phishing and identity theft.

Source: https://www.cpomagazine.com/cyber-security/ai-music-generating-platform-suno-data-breach-affects-over-55-million-people/

SonyAI cybersecurity rating report: https://www.rankiteo.com/company/sonyai

Suno cybersecurity rating report: https://www.rankiteo.com/company/sunomusic

Universal Music Group cybersecurity rating report: https://www.rankiteo.com/company/universalmusicgroup

"id": "SONSUNUNI1785256205",
"linkid": "sonyai, sunomusic, universalmusicgroup",
"type": "Breach",
"date": "1/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '55.3 million users',
                        'industry': 'Technology, Artificial Intelligence, '
                                    'Music',
                        'location': 'Cambridge, Massachusetts, USA',
                        'name': 'Suno',
                        'type': 'AI Music Generation Platform'}],
 'data_breach': {'file_types_exposed': ['Source code', 'Payment records'],
                 'number_of_records_exposed': '55.3 million',
                 'personally_identifiable_information': 'Email addresses, '
                                                        'phone numbers, names, '
                                                        'physical addresses, '
                                                        'partial credit card '
                                                        'details',
                 'sensitivity_of_data': 'High (personal and financial data, '
                                        'proprietary source code)',
                 'type_of_data_compromised': ['Email addresses',
                                              'Phone numbers',
                                              'Stripe payment records',
                                              'Internal source code']},
 'description': 'Suno, a Cambridge, Massachusetts-based AI music generation '
                'platform, has confirmed a data breach affecting over 55.3 '
                'million users. The incident exposed sensitive user '
                'information, including email addresses, phone numbers, and '
                'tens of thousands of Stripe payment records containing names, '
                'physical addresses, purchase amounts, and partial credit card '
                'details. The breach also revealed internal source code from '
                '2023–2024, confirming that Suno trained its AI models using '
                'copyrighted music scraped from platforms like YouTube, '
                'Deezer, and Genius. The company has not publicly acknowledged '
                'the breach or identified the attack vector.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Email addresses, phone numbers, Stripe '
                                'payment records (names, physical addresses, '
                                'purchase amounts, partial credit card '
                                'details), internal source code',
            'identity_theft_risk': 'High (phishing and identity theft risk due '
                                   'to exposed personal and financial data)',
            'legal_liabilities': 'Ongoing lawsuits from Sony Music, UMG '
                                 'Recordings, and Warner Records for copyright '
                                 'infringement',
            'payment_information_risk': 'High (partial credit card details '
                                        'exposed)'},
 'lessons_learned': 'Poor internal visibility and incident readiness, failure '
                    'to follow basic security practices, need for regular '
                    'penetration testing and robust controls',
 'post_incident_analysis': {'corrective_actions': 'Regular penetration '
                                                  'testing, enhanced '
                                                  'monitoring, robust controls',
                            'root_causes': 'Poor internal visibility, failure '
                                           'to follow basic security '
                                           'practices'},
 'recommendations': ['Publicly acknowledge the breach and provide transparency',
                     'Implement regular penetration testing',
                     'Enhance monitoring and incident response capabilities',
                     'Review and strengthen data protection measures'],
 'references': [{'source': 'Have I Been Pwned'},
                {'source': 'Seemant Sehgal, CEO of BreachLock'},
                {'source': 'Steven Swift, Suzu Labs'}],
 'regulatory_compliance': {'legal_actions': ['Lawsuits from Sony Music, UMG '
                                             'Recordings, and Warner Records '
                                             'for copyright infringement']},
 'response': {'communication_strategy': 'No public acknowledgment of the '
                                        'breach'},
 'title': 'Suno AI Music Platform Suffers Massive Data Breach, Exposing 55 '
          'Million Users',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.