Data breach at Suno affects over 55 million users
A quarter of all exfiltrated email addresses were already present in the Have I Been Pwned database.

Suno logo. By CFOTO/Future Publishing via Getty Images
- Suno leaked data from over 55 million users, including emails, phone numbers, addresses, purchases and partial card details.
- A hacker said they breached Suno by stealing one employee’s login credentials and accessing outdated source code.
- Suno did not notify affected users, saying individual notices were not required under applicable privacy laws.
- The breach adds pressure on Suno, which already faces music industry scrutiny over AI training and copyrighted material.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Late last year, AI music generator platform Suno leaked the personal information of over 55 million users.
According to 404 Media, the stolen data appeared on the internet last week.
The hacker responsible for the data breach, ellie.191, told the news outlet that they accessed the company’s systems by stealing a single employee’s login credentials.
The attacker then used the stolen credentials to access Suno’s outdated source code, which included instructions on how to scrape songs and lyrics from YouTube Music, Deezer, and Genius, as well as from the stock music libraries Pond5, Jamendo, Freesound, the International Music Score Library Project, and podcasts via RSS feeds.
In addition, Suno’s customer list was accessed, containing customers’ data, including email addresses, phone numbers, and Stripe payment information.
This all happened in November 2025. However, none of the affected users were informed of the breach when it all went down.
“Based on the limited nature of the customer information believed to be involved, we determined that individual notifications were not warranted under applicable privacy laws,” a Suno spokesperson said at the time.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Troy Hunt, a cybersecurity expert from Australia and founder of the infamous Have I Been Pwned database, says that the publicly released data from the Suno data breach contained 55.3 million unique email addresses, plus tens of thousands of Stripe payment records.
On top of that, Hunt found that names, phone numbers, purchases, physical addresses, and partial credit card data, such as the card type, expiry data, and the last 4 digits, were among the compromised data.
In a post on social media platform X, Hunt claims that 24% of all compromised email addresses were already present in the Have I Been Pwned database.
Suno has been involved in several major lawsuits from the record industry over the years, accusing the AI music generator platform of training its AI model with copyright-protected material.
“The music community has embraced AI, and we are already partnering and collaborating with responsible developers to build sustainable AI tools centered on human creativity that put artists and songwriters in charge. But we can only succeed if developers are willing to work together with us,” Mitch Glazier, Chairman and CEO of the Recording Industry Association of America, said at the time.
Suno stated that its model was trained on “essentially all music files of reasonable quality that are accessible on the open internet,” including “tens of millions of recordings.”
Last year, Warner Music Group and Suno reached an agreement, allowing users to create AI-generated music from artists who opted in for the use of their names, images, likenesses, voices, and compositions.
Mikey Shulman, CEO of Suno, argued that the partnership with Warner Music Group would provide new opportunities for music creators.