Suno AI Hacked: Source Code Exposes YouTube Scraping – Claril Noticias

AI music generator Suno suffered a major security breach in November, exposing source code that allegedly proves the company scraped decades of copyrighted audio from YouTube Music, Deezer, and Genius to train its models.

How the Suno AI Security Breach Unfolded

The cyberattack, first reported by 404 Media, involved a supply chain compromise. The hacker disclosed that they gained access to an employee’s credentials, which subsequently allowed them to view Suno’s proprietary source code. This compromised data allegedly reveals that the platform systematically scraped decades of audio content from YouTube Music, Deezer, Genius, various stock music libraries, and podcast RSS feeds to train its artificial intelligence.

The Fair Use Defence vs. Copyright Infringement

Suno has previously admitted to training its AI models using “publicly available music files” sourced from the open internet. The company maintains that training AI on copyrighted material is legally protected under the fair use doctrine. However, major record labels currently pursuing legal action against Suno argue that bypassing YouTube’s anti-scraping mechanisms is illegal under the Digital Millennium Copyright Act (DMCA), whilst also directly violating YouTube’s terms of service.

Broad Industry Backlash

Suno is not the only platform facing scrutiny over data acquisition practices. Its direct competitor, Udio, has also been accused of scraping audio from YouTube. Meanwhile, Google, the owner of YouTube, is dealing with its own copyright infringement allegations brought forward by several major book publishers.

Compromised Customer Data and Suno’s Response

Beyond the exposure of training methodologies, the hacker reportedly accessed sensitive user information. The compromised database includes customer emails, phone numbers, and partial credit card numbers stored via Stripe.

Despite the severity of the breach, Suno did not proactively notify its user base about the incident, which occurred in November. Instead, the firm characterised the breach as a “limited security incident that was quickly contained.”

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *