Data breach at Suno confirms over 55 million user accounts compromised

← Back to the feed

Data breach at Suno confirms over 55 million user accounts compromised

Developed over time first seen 2 months ago

The Register · 2 months ago

A data breach at AI music generator Suno has been confirmed to have exposed more than 55 million user accounts, after security researcher Troy Hunt's Have I Been Pwned service ingested the leaked files and put a concrete figure on the incident for the first time. The breach, first reported the previous week, matters both for its scale at a fast-growing AI platform and for what accompanying leaked material suggested about how Suno trained its models, reigniting long-running disputes over AI firms scraping copyrighted music and lyrics.

The leaked data consists mainly of email addresses and, where supplied at sign-up, phone numbers, while tens of thousands of Stripe payment records also expose names, physical addresses, purchase amounts and partial card details such as card type, expiry date and the last four digits. Whoever claimed the breach also released Suno source code from 2023-24 allegedly showing the company scraping songs and lyrics from YouTube Music, Deezer and Genius to train its AI; Suno has acknowledged training on music from the open internet and argues this is fair use, and did not respond to a request for comment. The episode adds to existing legal pressure on the firm: major labels, via the RIAA, sued Suno and rival Udio in 2024 for allegedly scraping songs without permission, with Warner Records since settling and striking a commercial partnership with Suno, while Sony Music and UMG continue to pursue their claims in court.

  • Have I Been Pwned confirms Suno breach exposed 55m+ accounts
  • Leaked data includes emails, phone numbers and partial Stripe card details
  • Leaked code allegedly shows AI training on scraped music; Sony, UMG still suing

New here? Start with this

Data breach at AI music generator Suno confirms over 55 million user accounts compromised, after security researcher Troy Hunt's Have I Been Pwned service verified the leaked files and put a firm number on an incident first reported the previous week. Suno is a fast-growing platform that lets users generate songs from text prompts using artificial intelligence, and the scale of the breach has drawn attention both for the number of people affected and for what leaked material alongside it appeared to reveal about the company's practices.

The exposed data is mostly email addresses and, in some cases, phone numbers, with a smaller set of payment records also showing names, addresses and partial card details. Alongside the user data, source code said to be from Suno's development in 2023 and 2024 was also released, which reportedly indicates the company took songs and lyrics from other music services to train its AI systems; Suno has previously said it trains on material from the open internet and considers this lawful.

This adds to an existing dispute between Suno and the wider music industry. Major record labels, coordinated through the Recording Industry Association of America, sued Suno and a rival AI company in 2024 over the unauthorised use of copyrighted songs in training their systems. One label has since settled and formed a business partnership with Suno, while others are still pursuing their case through the courts.

More coverage

AI Cybersecurity Entertainment Music Technology

Read the full article at the source →

Originally published by The Register as “AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert”.