AI music generation company Suno has confirmed a data breach that exposed personal information belonging to more than 55.3 million people, according to a disclosure tracked by breach notification service Have I Been Pwned. Suno said the intrusion occurred in November 2025 but the company did not publicly acknowledge it until the exposure surfaced this summer.
The stolen data included 55.3 million unique email addresses along with names, phone numbers, physical addresses, purchase records, and partial payment card details such as card type, expiration date, and the last four digits. Tens of thousands of associated Stripe payment records were also taken.
Investigators traced the intrusion to malware installed through third party code on a developer laptop. The attacker used stolen credentials tied to the Shai-Hulud supply chain worm to move from that single machine into Suno's broader cloud environment, eventually reaching customer records.
Beyond user accounts, the attacker also accessed portions of Suno's internal training data, which reportedly included lyrics and songs pulled from platforms such as YouTube Music, Genius, and Deezer. Suno is separately facing litigation from major record labels over the unlicensed use of copyrighted recordings to train its AI models.
Suno has not detailed what remediation steps it has taken for affected users or why the company waited several months to disclose the incident. Security researchers say the case illustrates how a single compromised developer credential can cascade into a company wide breach when access controls are not segmented.
Source: TechCrunch - https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/
