An immense cyberattack on AI music generator Suno in November 2025 has compromised the personal information of over 55.3 million users, according to data breach notification service Have I Been Pwned, exposing the vast scale of the security failure for the first time.
What Data Was Stolen in the Suno AI Breach?
The compromised dataset, which was obtained and analysed by Have I Been Pwned, contains highly sensitive customer credentials. The stolen information includes user names, physical addresses, email addresses, phone numbers, and purchase histories.
Furthermore, the hacker successfully exfiltrated partial payment card numbers and card expiry dates directly from the company’s Stripe account, putting millions of financial customers on high alert.
Source Code Leak Exposes Mass Scraping Allegations
Although the intrusion occurred in November 2025, the public only became aware of the incident following an investigation by independent news outlet 404 Media.
Beyond personal user data, the hacker also stole Suno’s proprietary source code. The leaked code reportedly reveals how the platform scraped millions of songs and lyrics from major streaming and media sites, including Deezer, Genius, and YouTube, to train its AI music models. This discovery arrives amidst intense legal pressure, as several major record labels are currently suing Suno for copyright infringement over these unauthorised data-scraping practices.
Suno’s Silence and Corporate Response
Suno has not yet published an official data breach notice on its website, nor has it proactively notified the millions of individuals whose details were stolen. Suno co-founder Mikey Shulman did not respond to requests for comment regarding the security incident.
Following the publication of the breach, Suno spokesperson Rachel Racusen confirmed that the company did experience a security incident in November 2025. While Racusen did not dispute the figure of 55.3 million affected users, the company has declined to explain why the incident has not been publicly acknowledged on its platform, and failed to confirm whether any direct communications have been sent to the victims.
