Safety

Data breach at Suno exposed 55.3 million users' personal details

A November 2025 security breach at AI music generator Suno exposed personal data for 55.3 million people, according to Have I Been Pwned.

Data breach at Suno exposed 55.3 million users' personal details

According to Have I Been Pwned, AI music generator Suno experienced a security breach that exposed personal data for 55.3 million people. The attack occurred in November 2025 and was reported publicly in July 2026 by 404 Media. Suno has not issued a public notification to users, and its spokesperson did not dispute the reported figure.

What data was exposed

Available information indicates the leaked records included:

  • full names
  • home addresses
  • phone numbers
  • purchase histories
  • partial card numbers and expiry dates taken from Suno's Stripe account

Have I Been Pwned cited the total of 55.3 million affected records; Suno’s spokesperson did not contest that number.

Timeline and company response

The breach itself dates to November 2025, but it only reached public attention in July 2026 after reporting by 404 Media. Suno has not posted an official disclosure for users, and there is no public record of the company notifying affected individuals directly.

Reports also say the attacker obtained portions of Suno’s source code. That code reportedly showed Suno scraping content and metadata from other services such as Deezer, Genius and YouTube—practices that have already prompted litigation from record labels.

Legal and practical implications

Many U.S. states require data breach notifications to be issued within 60 days. The roughly eight-month gap between the November 2025 intrusion and the July 2026 public report exceeds that typical statutory window by a substantial margin.

The types of leaked data — notably home addresses and partial payment details — increase the risk of identity theft, fraud and targeted abuse for those affected. The presence of questionable data collection practices in the source code may also intensify legal exposure for Suno in ongoing disputes with rights holders.

Why this matters

Suno’s service generates music from text prompts; it is not evident why the company retained home addresses for 55 million people. Equally notable is that many affected users learned about the compromise from a news article rather than a direct notice from Suno.

The case highlights broader concerns about data handling and transparency at AI-driven services and underscores the importance of timely breach disclosure by companies.

What to watch next

Observers should monitor any official statements from Suno, regulatory inquiries, and court cases tied to the reported scraping behavior and copyright claims. Affected users should watch their bank and card statements for suspicious activity and consider filing fraud reports if they detect misuse.


(Reported sources: Have I Been Pwned, 404 Media, Suno, Stripe; breach date: November 2025; public reporting: July 2026.)