共有:

AI Music / Data Breach

Suno breach exposes
data on 55 million accounts

A large-scale leak of Suno user data has been reported by UK tech outlet The Register. The trail leads back to the same intrusion behind a source-code leak that surfaced in mid-July.

AI Navigate Editorial2026.07.226 min read

Intrusion Nov 2025 Code leak reported Jul 15, 2026 Added to HIBP Jul 20, 2026 The Register reports Jul 21, 2026
01
The Breach

55.3 million records
landed in Have I Been Pwned

UK tech outlet The Register reported on July 21, 2026 that user data from AI music service Suno had leaked at scale. The exposure came to light after Troy Hunt, the security researcher behind breach-notification service Have I Been Pwned (HIBP), added more than 55.3 million account records to the database on July 20.

Most of the leaked data consists of email addresses and phone numbers, but tens of thousands of records tied to payment processor Stripe also included names, physical addresses, purchase amounts, and partial payment details such as card type, expiry date, and the last four digits. Suno has not individually notified affected users, saying "individual notices are not required under applicable law."

02
By The Numbers

The breach, by the numbers

55.3M
accounts exposed in the leak
Nov 2025
month of the initial intrusion
113,879h
audio scraped from YouTube
03
Source Code Leak

Where the training data
came from, spelled out in code

Source code taken through the same intrusion, reported in mid-July, itemized exactly how Suno gathered its training data.

This user-data leak is not an isolated incident. According to a 404 Media report published July 15, a hacker going by "ellie.191" broke into Suno's internal systems in November 2025 by stealing an employee's credentials via Shai-Hulud, a supply-chain worm. The 55-million-account leak now coming to light appears to trace back to the access gained at that time.

The stolen source code itemized Suno's training-data pipeline: roughly 2 million video clips — totaling 113,879 hours — scraped from YouTube, plus 62,117 hours from stock-audio service Pond5, 17,615 hours of lyric data from Genius, and 12,287 hours of songs from music service Deezer. Music Business Worldwide notes this could bolster allegations of unauthorized training-data use in the copyright lawsuits Universal, Sony, and Warner have brought against Suno.

113,879h YouTube 62,117h Pond5 17,615h Genius 12,287h Deezer
FIG. Hours of scraped training audio by source, per the leaked code (bars approximate; exact figures per label)
04
Who's Affected

Business use carries
the bigger risk

How much this matters depends on how you use Suno. Here's what each type of reader should do.

Leadership & IT

If your organization runs Suno on a team or business account, reset any reused password immediately and turn on two-factor authentication. Because some Stripe payment data was included, check statements for cards linked to the account.

Marketing & Social

Teams using Suno for campaign production should watch for phishing targeting the registered email. Copyright exposure — tied to how the RIAA lawsuit plays out — is also worth weighing before renewing a commercial-use contract.

Product & Vendor Selection

When evaluating a generative-AI vendor, data-governance practices and how transparently they disclose incidents now belong alongside features and price as selection criteria.

Personal / casual useBusiness / team use
Leaked data is mostly email and phone — real-world harm is limitedStripe payment details and internal contacts may be exposed
Changing a reused password is largely sufficientRequires 2FA, card reissue, and internal notification
Copyright exposure from outputs stays within personal-use scopeCommercial use ties business risk directly to the RIAA lawsuit's outcome

The faster a service grows,
the later its shaky foundations surface.


05
What's Next

Generative AI's growth
has outpaced its governance

Suno scaled its user base rapidly from late 2024 through 2025. What this incident reveals is that, behind that growth, credential management for employees — and security around vendor relationships like Stripe that handle user data — hadn't kept pace. Many generative-AI companies are in a similarly rapid growth phase, so this may not stay a Suno-only problem.

What happens next hinges on how far Suno extends individual notification or remediation now that the data is in HIBP, and whether this leaked source code is admitted as evidence in the RIAA lawsuit. In the meantime, the practical steps for users are: (1) change your Suno password and stop reusing it elsewhere, (2) check your registered email address on Have I Been Pwned, and (3) if this is a work account, report it to your security team right away.

A caveat is worth stating plainly: the exposed payment data is limited to the last four digits and expiry date, not full card numbers, and no confirmed cases of fraudulent use have surfaced yet. Likewise, the training-data breakdown revealed in the source code does not by itself establish copyright infringement as a legal matter — it functions as one piece of circumstantial evidence in an ongoing case, not a verdict.