Suno Waited Eight Months to Tell 55 Million Users About a Data Breach

A new survey found most Americans don't want AI-made entertainment, signaling continued skepticism toward artificial intelligence in music and media.

August 6, 2026

In November 2025, a hacker using the name ellie.191 infected a Suno employee’s device with Shai-Hulud, a supply-chain worm that steals GitHub and cloud-service credentials, and used those credentials to access Suno’s internal systems. The attacker walked away with the personal data of more than 55 million users and the company’s source code. Suno determined it had been breached, conducted an internal investigation, concluded that “no sensitive personal information was compromised,” and told no one. Eight months later, breach notification service Have I Been Pwned added 55,282,226 unique email addresses from Suno’s systems to its database on July 20, after independent outlet 404 Media broke the story on July 15. The public learned about the breach from a data breach monitoring service and an independent reporter. Not from Suno.

The scope of what was exposed is broader than Suno’s initial characterization suggested. According to Have I Been Pwned and reporting by TechCrunch, the stolen dataset contained more than 55 million unique email addresses, phone numbers where users had provided them at sign-up, and tens of thousands of Stripe purchase records containing customers’ names, physical addresses, purchase amounts, and partial payment card details including card type, expiry date, and the last four digits of the card number. Roughly 24% of the email addresses had already appeared in previous breaches, meaning the remaining 76% were new additions to the compromised record. Suno told 404 Media it does not have access to customers’ full credit card numbers in Stripe, which is accurate but does not address the physical addresses, names, and purchase histories that were also in the dataset.

Suno’s explanation for why it did not notify users is worth examining carefully. A spokesperson told 404 Media that the company “immediately conducted an investigation and verified that the incident primarily involved outdated source code that is no longer in use at Suno and that no sensitive personal information was compromised,” and that individual breach notifications “were not warranted under applicable privacy laws.” After TechCrunch published its report on July 21, spokesperson Rachel Racusen did not dispute the 55 million figure and confirmed the security incident, but the company had not publicly acknowledged the breach on its own website and did not provide TechCrunch with any communication it may have sent to users. The gap between “outdated source code” and 55 million exposed records is not a small one, and cybersecurity experts have noted that physical addresses and purchase records are exactly the category of data that consumer privacy statutes in states including California were designed to protect.

Related Stories

The source code component of the breach is where the copyright litigation dimension enters the picture. The leaked code, reviewed by 404 Media and reported in detail by The Register, showed Suno had scraped songs and lyrics from YouTube Music, Deezer, and Genius, along with stock music libraries including Pond5, Jamendo, Freesound, and the International Music Score Library Project. One file logged 2,013,545 music clips from YouTube Music. The total volume across sources amounted to hundreds of thousands of hours of audio. That is not a theoretical training pipeline. It is a documented, operational scraping architecture, now in the hands of whoever bought, copied, or received the stolen data, and available to any journalist or litigant who obtained it from 404 Media’s reporting. For UMG and Sony Music’s pending copyright case against Suno in Massachusetts, where the two labels have been fighting for months to establish the precise scope of Suno’s training data, the leaked source code is the most concrete evidence yet of exactly the information they have been seeking through discovery.

Suno was hit with a proposed class action over the breach on July 24 in the US District Court for the District of Massachusetts, where the company is headquartered. Named plaintiff Alec Pilavian, a Florida Suno customer, is seeking to represent all US users whose data was compromised. The complaint accuses Suno of relying on “cheap, ineffective security measures” and seeks damages plus a court order requiring at least ten years of credit monitoring for class members. A Suno spokesperson told Music Business Worldwide the incident “primarily involved outdated source code and a limited amount of information associated with certain users,” reiterating that the company does not store full payment card information or bank account details and that it had hired a third-party cybersecurity firm to audit its initial findings.

The breach lands at one of the most legally and commercially exposed moments in Suno’s history. A German court found Suno liable for copyright infringement in GEMA’s lawsuit on July 31, the first such ruling in Europe. The Hagens Berman class action on behalf of independent artists is expanding. The AFM’s lawsuit against UMG and Warner over session musician exclusion from AI licensing deals is proceeding in New York. And Suno is simultaneously defending its fair use argument in Massachusetts while the source code breach has now handed opposing counsel a detailed map of exactly what it trained on and where it came from. The company raised $400 million at a $5.4 billion valuation in June. It now faces a data breach class action, a German copyright judgment, two major label lawsuits, an independent artist class action, and a source code leak that has done more to answer the music industry’s training data questions than eight months of litigation discovery combined.

Related Stories

It seems we can’t find what you’re looking for.

Related Stories

It seems we can’t find what you’re looking for.

Related Stories

It seems we can’t find what you’re looking for.

Related Stories

It seems we can’t find what you’re looking for.

FTM Newsletter

Sign Up for the Weekly Flare Newsletter so they news comes to you!

Trending

Weekly flare

A weekly briefing on what matters in the music industry

By providing your information, you agree to our Terms of Service and our Privacy Policy. We use vendors that may also process your information to help provide our services

You Might Also Like

Get the Today in Entertainment Newsletter

A weekly brief about what matters and what's interesting in Music

By providing your information, you agree to our Terms of Service and our Privacy Policy. We use vendors that may also process your information to help provide our services.