A data breach at AI music generator Suno exposed the personal information of 55.3 million people, according to Have I Been Pwned. The breach happened in November 2025 but was only revealed publicly in July 2026 through reporting by 404 Media.

What makes this breach particularly troubling: Suno never notified affected users. The company stated that individual notices were not required under applicable privacy laws.
What Got Stolen
The stolen dataset, which appeared on the internet in July 2026, contained:
- 55.3 million unique email addresses
- Customer names and physical addresses
- Phone numbers
- Purchase history records
- Partial payment card numbers and expiry dates from Stripe
- Source code revealing training data scraping methods
Troy Hunt, founder of Have I Been Pwned, confirmed the breach after obtaining a copy of the dataset. He noted that 24% of the email addresses were already in the HIBP database from other breaches, but the remaining 76% were new.
How the Breach Happened
According to reporting, the intrusion was traced to stolen employee credentials rather than a direct attack on Suno’s production systems. A single compromised employee login gave the attacker access to the data and Suno’s source code.
The source code revealed how Suno allegedly scraped millions of songs and lyrics from streaming platforms including Deezer, Genius, and YouTube to train its AI music models. This adds fuel to ongoing copyright lawsuits filed by major record labels against the company.
Eight Months of Silence
Suno’s response has drawn sharp criticism. After TechCrunch published its story, Suno spokesperson Rachel Racusen did not dispute the 55.3 million user figure and confirmed the company experienced a security incident in November 2025. However, the company has not publicly acknowledged the breach on its website and has not provided evidence of any user notification.
The breach data includes records from users who signed up for Suno’s free tier as well as paying subscribers. The Stripe payment records specifically affected customers who entered card details for premium plans.
Broader Context
The Suno breach ranks among the largest AI company data breaches recorded. It follows a pattern of AI startups growing rapidly without commensurate investment in security infrastructure.
At the time of the breach, Suno had recently raised $400 million in funding. The company is simultaneously facing copyright infringement lawsuits from major record labels who allege Suno’s scraping of copyrighted music violated intellectual property law.
Users who ever created a Suno account should immediately check their email on Have I Been Pwned, change their password if they reused it elsewhere, and monitor financial statements for unauthorized charges related to the exposed Stripe payment data.
Frequently Asked Questions
When did the Suno data breach happen?
The breach occurred in November 2025, but the data only appeared publicly in July 2026 through 404 Media’s reporting.
What personal data was exposed in the Suno breach?
Names, email addresses, physical addresses, phone numbers, purchase records, partial payment card numbers, and expiry dates from Stripe were all included in the stolen dataset.
Did Suno notify affected users?
No. Suno stated that individual notices were not required under applicable privacy laws and has not publicly acknowledged the breach on its website.
How many users were affected?
55.3 million unique email addresses were found in the dataset, confirmed by Have I Been Pwned founder Troy Hunt.
How can I check if my Suno data was exposed?
Visit haveibeenpwned.com and search for your email address. Suno was added to the database on July 20, 2026.
