Technology

AI Music App Suno Was Hacked: What Happened to 55 Million Users' Data

Martin HollowayPublished 8h ago4 min readBased on 2 sources
Reading level
AI Music App Suno Was Hacked: What Happened to 55 Million Users' Data

A cyberattack against AI music generator Suno compromised the personal and financial data of more than 55.3 million users, according to the breach-tracking service Have I Been Pwned, which disclosed the incident on July 20, 2026. The breach actually happened in November 2025. As of July 21, 2026, Suno had not publicly disclosed the incident or notified the people affected.

Have I Been Pwned is a free website where people can check if their personal information has been exposed in a data breach. The service obtained a copy of the stolen Suno data and published a page at haveibeenpwned.com/Breach/Suno. The stolen information included customers' names, home addresses, email addresses, phone numbers, purchase records, and partial credit card numbers with expiry dates. The credit card data came from Suno's Stripe account — Stripe being a company that processes online payments. The stolen data also included Suno's source code, which is the set of programming instructions that runs the service.

The breach was originally reported by independent news outlet 404 Media. TechCrunch contacted Suno co-founder Mikey Shulman for comment; he did not respond.

The stolen source code allegedly revealed that Suno copied millions of songs and lyrics from Deezer, Genius, and YouTube to train its AI models. Several major record labels are currently suing Suno, claiming that copying all that music without permission violates copyright law. If the exposed source code proves to be genuine, it could serve as evidence in that lawsuit.

The partial credit card numbers and expiry dates, even without full card numbers, could help attackers carry out scams. Combined with names, addresses, and phone numbers, this kind of information can be used to trick people into revealing more details or to try stolen passwords on other websites. Because the credit card data came through Stripe, the breach appears to have reached Suno's payment system, not just a basic user database. The fact that source code was also stolen means that the inner workings of Suno's AI training, its music-copying tools, and its system architecture may now be visible to whoever holds the data.

The eight-month gap between the breach happening and the public learning about it raises its own questions. Under most U.S. state laws and the EU's data-protection rules (known as GDPR), companies are required to notify affected people and regulators within a set timeframe after a breach involving personal data. Suno's apparent silence through July 2026 raises questions about whether the company could face regulatory penalties in addition to the reputational harm.

The timing also matters because of the ongoing copyright lawsuit. Several major record labels are suing Suno over how it gathered training data. If the source code found in the breach is entered into court as evidence, it could give the record labels clear proof that Suno copied music from Deezer, Genius, and YouTube — rather than having to argue the point based on guesses or outside analysis.

The broader context here is something we have watched build across the AI industry over the past several years. AI companies face pressure on two fronts: the data they use to build their models is increasingly challenged on copyright grounds, and the personal data they collect from users faces growing security and privacy rules. Suno now faces both pressures at the same time. A breach that reveals how a company gathered its training data while that company is being sued for copyright violations is an unusually intense version of a risk many AI companies carry to some degree.

For people who may have used Suno, the Have I Been Pwned website is the most direct way to check whether their data was included. Since Suno has not sent its own notification, that website is currently the main place to find this information.

Looking at what this means for the AI industry more broadly, the Suno incident points to a pattern worth taking seriously. AI companies often hold two kinds of sensitive information: users' personal and payment data, and the company's own source code and training methods. A single breach can expose both. The fix is simple to describe, if harder to carry out: keep payment data stored separately from source code and training systems, so that if an attacker breaks into one, they do not automatically get the other. Whether Suno had that kind of separation in place is not publicly known.

What is known is that 55.3 million people had their personal and partial financial data exposed in a breach their service provider chose not to disclose, and that the same breach may have handed copyright plaintiffs a clearer view of how their content was used.