Safety

Suno data breach exposed personal details of 55.3 million users

A November 2025 cyberattack on AI music generator Suno compromised personal information of 55.3 million people, according to Have I Been Pwned, which reviewed the stolen dataset.

Suno data breach exposed personal details of 55.3 million users

A AI music generator Suno suffered a cyberattack in November 2025 that exposed personal information for more than 55.3 million people, according to the breach-notification service Have I Been Pwned, which obtained a copy of the stolen dataset and reviewed its contents.

What was stolen?

Have I Been Pwned reports that the compromised dataset included customers’ names, physical addresses, email addresses, phone numbers, purchase records, and partial payment card details taken from Suno’s Stripe account, including card expiry dates.

Source code and large-scale scraping evidence

The leaked materials also contained Suno’s source code. According to the code, the company allegedly scraped millions of songs and lyrics from popular streaming and lyric sites — including Deezer, Genius and YouTube — to train its AI models. Several major record labels have filed lawsuits against Suno, claiming its mass-scraping activities violate copyright law.

Communication and company response

The breach was revealed publicly after reporting by independent outlet 404 Media; Suno initially had not publicly disclosed the incident or notified affected individuals. Suno co-founder Mikey Shulman did not respond to TechCrunch’s request for comment.

After publication, Suno spokesperson Rachel Racusen did not dispute the figure of 55.3 million users and confirmed that the company experienced a security incident in November 2025. The company has not posted an explicit public breach notification on its website, and when asked by TechCrunch did not provide any communication it may have sent to users informing them of the breach.

Why this matters

The incident is significant both as a large-scale personal data breach and as potential evidence in ongoing copyright litigation. The exposure of personal identifiers and payment information poses privacy and security risks for millions of users, while the leaked source code and scraping records may strengthen legal claims by record labels.

Timeline (key points)

  • November 2025: security incident affecting Suno, per Have I Been Pwned’s assessment of the stolen dataset.
  • 2026 (public disclosure): reporting by 404 Media made the incident public; Have I Been Pwned reviewed the leaked data.
  • Post-publication: Suno spokesperson Rachel Racusen confirmed the security incident and did not dispute the 55.3 million figure, but the company has not issued a formal public notice on its site or shared user notifications with TechCrunch.

Next steps

Observers will be watching the progress of the lawsuits from record labels, any regulatory inquiries, and whether Suno issues detailed disclosures or notifications to users — developments that will influence both the company’s legal exposure and wider industry practices around data handling and training data collection.