Personal data belonging to more than 55.3 million people was compromised in a November 2025 breach of AI music generator Suno, according to information from breach notification service Have I Been Pwned.
Breach Details
The exposed records included names, physical addresses, email addresses, phone numbers and purchase histories. Partial payment card data from Suno’s Stripe account was also among the compromised information, revealing card types, expiry dates and the last four digits of card numbers.
Have I Been Pwned said the dataset contained more than 55 million unique email addresses, with phone numbers exposed where they had been used as a sign-up method.
“Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data, including the card type, expiry date, and last four digits.”
Suno told Have I Been Pwned that it does not have access to customers’ full credit card numbers through Stripe. The service advised affected users to change their passwords and activate two-factor authentication where available.
Source Code and Training Data Exposed
The stolen data also contained portions of Suno’s source code, offering a window into the material scraped from online platforms to train its artificial intelligence models. The code, which appears to date from 2023 and 2024, references more than 2 million music clips and content sourced from YouTube, Deezer and Genius.
Specifically, the references included over 113,000 hours of YouTube Music content, 17,000 hours of Genius material and 12,000 hours of Deezer content.
Legal Pressure and Disclosure
The revelations surface as Suno faces a lawsuit from major record companies over its use of copyrighted music to train AI systems. The labels argue that the company’s scraping of music did not qualify as fair use and infringed copyright.
Suno had not publicly disclosed the security incident or directly notified affected users before reports of the breach emerged. A company spokesperson later confirmed that Suno experienced a security incident in November but did not dispute the reported number of affected users.
The breach adds to ongoing scrutiny of AI music companies over both data security and the sources of copyrighted material used to develop generative AI systems.