Suno Data Breach Exposed Personal Information of 55 Million Users

A cyberattack on AI music generator Suno in November 2025 resulted in the theft of personal data belonging to more than 55.3 million people, according to data breach notification service Have I Been Pwned, which obtained a copy of the stolen dataset.

The breached data included customers’ names, physical addresses, email addresses, phone numbers, purchase records, and partial payment card numbers — including card expiry dates — taken from the company’s Stripe account.

The breach was not publicly known until recently, when independent news outlet 404 Media reported on it. Suno has not publicly disclosed the cyberattack and has not notified affected individuals that their information was taken. Suno co-founder Mikey Shulman did not respond to a request for comment from TechCrunch.

The stolen data also included Suno’s source code, which reportedly revealed that the company scraped millions of songs and lyrics from popular streaming platforms — including Deezer, Genius, and YouTube — to train its AI models. Several major record labels are currently suing Suno, alleging that this mass-scraping activity violates copyright law.

With over 55 million users potentially affected and no official disclosure from the company, this breach may leave a large number of individuals unaware that their personal and partial financial information has been compromised. The exposure of Suno’s source code alongside customer data adds a further dimension to the incident, given the ongoing legal scrutiny the company already faces over its AI training practices.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top