AI music generator Suno experienced a cyberattack in November 2025 that compromised the personal information of more than 55 million customers, according to a newly surfaced data set.
The exposed records include customer addresses and, for those who signed up with a phone number, their phone numbers. A smaller portion of the data contained tens of thousands of Stripe payment records, revealing names, physical addresses, purchase amounts, and partial credit card details: card type, expiry date, and the last four digits. Suno stated that it does not have access to full credit card numbers within Stripe.
Stolen files also included Suno’s source code, which showed that the company scraped content from platforms such as YouTube, Deezer, and Genius to train its AI model.
Suno spokesperson Rachel Racusen confirmed the November 2025 security incident and did not dispute the reported number of affected users. The company has not posted a public notice about the breach on its website and, when asked, did not share any communication it may have sent to users regarding the incident.