Suno breach exposes data tied to more than 55 million accounts
Have I Been Pwned says the AI music platform’s leaked data includes emails, some phone numbers and tens of thousands of Stripe records.
By Dominic Okoye · Staff Writer
· 3 min read
AI music platform Suno has had data tied to more than 55 million user accounts exposed in a breach, according to Troy Hunt’s Have I Been Pwned service. The incident matters beyond account security because the person claiming responsibility also alleged that Suno’s own code shows large-scale scraping of music and lyrics, an issue already central to litigation against the company.
Have I Been Pwned said it had ingested the leaked files and published the first clear count of the breach’s scale since the incident became public last week. The bulk of the dataset consisted of email addresses, the service said. Phone numbers were present in cases where users had registered with a number instead of an email address.
The files also included tens of thousands of Stripe records, according to Have I Been Pwned. Those records exposed names, physical addresses and purchase amounts, along with partial payment card information including card brand, expiration date and the final four digits of card numbers.
Suno did not immediately respond to a request for comment from The Register. The company has not, based on the available reporting, disclosed its own account of how the data was accessed, how many paying customers were affected or whether any internal systems remain at risk.
Leak renews scrutiny of Suno’s training data
The person who claimed responsibility for the breach also provided what they described as Suno source code from 2023 and 2024. They claimed the code showed the company scraping millions of songs and lyrics from services including YouTube Music, Deezer and Genius for AI training.
That claim has not been tested in court through the breach material. Suno has previously acknowledged that it trained its models on music available on the open internet and has argued that the practice is protected as fair use.
The distinction is material for AI companies building generative media tools. Suno is already one of the more visible companies in AI-generated music, and the breach adds a security failure to an unresolved copyright fight over how the product was built.
Labels are still fighting Suno in court
Major record labels, represented by the Recording Industry Association of America, sued Suno and rival Udio in 2024. The labels allege the companies copied songs at scale without permission from copyright holders.
The plaintiffs included Sony Music Entertainment, UMG Recordings and Warner Records. Those companies represent artists including Bruce Springsteen, Beyoncé, Taylor Swift and Dua Lipa.
Warner has since settled with Suno and started a commercial partnership with the company. Sony and UMG are continuing their claims in court.
The breach lands after record labels had already raised complaints about AI companies’ mass data scraping and alleged copyright infringement before Suno’s November 2025 breach. For Suno, the immediate problem is user and payment-adjacent data exposure. The longer-running business risk is that leaked technical material, if authenticated and relied on in disputes, could sharpen questions about whether its training pipeline was lawful.
This story draws on original reporting from The Register.