17 days ago
TechCrunch Jul 21, 2026

AI music generator Suno breach affects 55M users, per Have I Been Pwned

The AI music generation platform Suno suffered a significant data breach in November 2025, impacting more than 55.3 million users, according to the breach notification service Have I Been Pwned. The stolen information included personal details such as names, physical addresses, emails, phone numbers, and partial payment card data from Suno’s Stripe account, including card expiration dates. The breach remained undisclosed by Suno until recent reports by independent outlet 404 Media brought it to light.

In addition to personal user data, the hacker also accessed Suno’s source code, which shed light on how the company reportedly scraped millions of songs and lyrics from major streaming services like Deezer, Genius, and YouTube to train its AI models. This revelation adds context to ongoing legal battles with several major record labels, who have sued Suno over alleged copyright violations stemming from these mass-scraping activities.

Despite the severity and scale of the breach, Suno had not publicly announced the cyberattack or directly informed its affected users at the time of reporting. Requests for comment from Suno's co-founder, Mikey Shulman, went unanswered, though a later statement from spokesperson Rachel Racusen confirmed the occurrence of a security incident in November 2025 without explaining the delayed disclosure.

This breach raises serious concerns about the security and privacy practices of AI companies like Suno that handle vast amounts of sensitive user data. As cyberattacks grow increasingly common, the need for transparency and prompt notification protocols becomes critical for maintaining user trust, especially for innovative tech services integrating AI into creative industries.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.