AI Music Platform Suno Suffers Data Breach Exposing 55 Million Users
AI music generation platform Suno has experienced a significant data breach, compromising the personal information of over 55 million users and tens of thousands of payment records.

AI music platform Suno has been hit by a data breach that exposed the personal details of more than 55 million users, according to Troy Hunt's Have I Been Pwned (HIBP) service. The compromised data primarily includes email addresses, with phone numbers also affected for users who provided them. In addition to user accounts, the breach also impacted tens of thousands of Stripe records, revealing sensitive payment information such as names, physical addresses, purchase amounts, and partial credit card data, including card type, expiry dates, and the last four digits of card numbers.
The scale of the breach was quantified by HIBP after the incident was first reported last week. The individual claiming responsibility for the breach also provided source code, reportedly from 2023 and 2024, which they alleged demonstrated Suno's practice of scraping millions of songs and lyrics from various online services, including YouTube Music, Deezer, and Genius, to train its AI models. Suno has previously acknowledged using music available on the open internet for training, asserting that such use constitutes fair use under copyright law.
This incident occurs against a backdrop of ongoing legal and ethical debates surrounding the use of AI in creative industries. Major record labels have voiced concerns about mass data scraping and copyright infringement by AI companies for months. In 2024, record labels, represented by the Recording Industry Association of America (RIAA), filed lawsuits against Suno and its competitor Udio, accusing them of unauthorized mass scraping of copyrighted music.
Among the plaintiffs in the legal action were prominent music corporations such as Sony Music Entertainment, UMG Recordings, and Warner Records, representing a wide array of globally recognized artists. While Warner has since reached a settlement with Suno and established a commercial partnership, Sony and UMG continue to pursue their legal claims in court.
The breach raises significant questions about data security practices within AI development companies, particularly those that rely on vast datasets scraped from the internet. The exposure of user data, coupled with allegations of extensive copyright infringement for AI training, places Suno at the center of a complex intersection of technology, intellectual property, and privacy concerns.
As the legal battles continue and regulatory scrutiny intensifies, incidents like the Suno data breach underscore the critical need for robust security measures and transparent data handling policies in the rapidly evolving AI landscape. The compromise of user information and payment details highlights the direct impact on individuals and the financial implications for companies operating in this space.
Suno has not yet responded to requests for comment regarding the specifics of the breach and the data exposed. The company's acknowledgment of using publicly available internet music for training, while defending it as fair use, remains a contentious point in ongoing litigation and industry discussions.