Suno, a leading AI-powered music generation platform, has confirmed exposure of personal data belonging to more than 55.3 million users following a major cyberattack. The breach was surfaced by the data breach monitoring service Have I Been Pwned and first reported by TechCrunch, with additional investigation by 404 Media placing the original intrusion as far back as November 2023. It ranks among the largest data breaches in the history of AI startups, and it carries an unusual second payload: the theft of Suno's own source code.
What Happened
According to reporting from TechCrunch and an investigation by 404 Media, attackers breached Suno's systems in November 2023, but the full scale of the compromise has only recently come to light. The delay between initial intrusion and public disclosure means affected users have potentially been exposed for well over a year and a half without notification.
Beyond harvesting user records, the attackers exfiltrated the source code of the Suno platform itself. Analysis of that code reportedly revealed that the company had scraped millions of songs and lyrics from platforms including Deezer, Genius, and YouTube to train its AI models. As of publication, Suno's leadership, including co-founder Mikey Shulman, has not issued an official statement on the incident.
What Was Taken
The stolen dataset is broad and highly sensitive. Confirmed compromised data includes:
- Full names of users
- Physical mailing addresses
- Email addresses
- Phone numbers
- Purchase records pulled from the company's Stripe payment integration
- Partial payment card data, including the last digits and expiration dates of bank cards
The combination of identity, contact, and financial data creates a serious risk profile for the more than 55 million affected individuals. Separately, the theft of Suno's proprietary source code represents a distinct intellectual property and legal exposure for the company.
Why It Matters
This incident is significant on multiple fronts. For defenders, it is a reminder that AI startups scaling rapidly often accumulate massive troves of personal and financial data while security maturity lags behind growth. A breach dwelling undetected since late 2023 points to gaps in monitoring, logging, and incident response.
The source code theft compounds the damage. Several major record labels have already sued Suno for copyright infringement, alleging illegal use of artists' intellectual property to train its models. The leaked code, which reportedly documents the scraping of copyrighted material, could become evidence in those proceedings. A breach that simultaneously exposes customers, exposes source code, and strengthens the case against the company in active litigation is a worst-case convergence of security, legal, and reputational risk.
The Attack Technique
Public reporting has not yet detailed the initial access vector or the specific tactics used to move through Suno's environment. What is known is that the intrusion dates to November 2023 and that attackers achieved deep access, exfiltrating both large-scale user databases and internal source code repositories. The ability to reach both production customer data and proprietary code suggests either broad lateral movement following an initial foothold or access to a shared or insufficiently segmented environment. Until Suno issues a technical disclosure, the exact entry point remains unconfirmed.
What Organizations Should Do
- Assume exposure and reset credentials. Users of Suno should change their account passwords immediately and rotate any credentials reused on other services.
- Watch for financial fraud. Because partial card data and Stripe purchase records were taken, affected users should monitor bank statements, enable transaction alerts, and consider a credit freeze.
- Brace for targeted phishing. The mix of names, addresses, emails, and phone numbers is ideal fuel for convincing phishing and smishing campaigns. Treat unsolicited messages referencing Suno with suspicion.
- Segment sensitive assets. Organizations should isolate source code repositories from production data stores and enforce least-privilege access so a single compromise cannot reach both.
- Invest in detection and dwell-time reduction. A breach undetected for over a year underscores the value of continuous monitoring, anomaly detection, and regular threat hunting.
- Audit third-party and training data pipelines. AI companies should verify that data ingestion practices are legally sound and that payment integrations like Stripe are configured to minimize retained cardholder data.
Sources: Suno AI service hit by cyberattack: 55 million user records stolen – Zamin.uz, 21.07.2026