55 million Suno users had their personal data stolen and the company stayed silent for months

55 million Suno users had their personal data stolen and the company stayed silent for months

A hacker stole the personal details of 55.3 million Suno users back in November 2025, yet the AI music generator has not told those affected. The breach included names, addresses, emails, phone numbers, purchase histories, and partial credit card numbers with expiry dates. The stolen data also contained Suno’s source code, which reportedly shows the company scraped songs and lyrics from YouTube, Deezer, and Genius to train its AI models.

The breach only came to light after independent outlet 404 Media reported it, and the scale was confirmed by Have I Been Pwned, which obtained the leaked dataset. Suno has not publicly acknowledged the attack, nor has it notified users, despite the severity of the exposure. This silence is concerning, especially since the data could be used for identity theft or targeted scams.

Suno is already facing lawsuits from major record labels over claims that its AI models were trained on copyrighted music without permission. The source code leak now provides potential evidence for those cases, as it allegedly reveals how the scraping was done. The company, co-founded by Mikey Shulman, has raised hundreds of millions in funding but has yet to address the breach or its implications.

Suno is a popular AI tool that lets users create songs with simple text prompts, attracting millions of users with its ease of use. The company’s rapid growth and reliance on scraped data have made it a lightning rod for legal and ethical debates in the music industry. This breach adds another layer of controversy, as it exposes not just user data but also the inner workings of its AI training process.

You should care because your personal information might be in the hands of hackers if you ever used Suno, and the company hasn’t warned you. Beyond that, this raises bigger questions about how AI companies handle both user privacy and copyrighted material, especially when their own security fails. The fact that Suno hasn’t disclosed the breach yet could also delay steps you might take to protect yourself, like changing passwords or monitoring bank statements.

What happens next depends on whether Suno finally speaks up. Users should watch for official notices, though the damage may already be done. Lawyers for the record labels suing Suno will likely dig into the leaked code, and regulators might step in over the lack of transparency. Meanwhile, affected users are left wondering if their data is being sold or exploited.

Did Suno fail its users by not disclosing this breach sooner, or is the company just another victim of an increasingly common cyber threat. Should AI companies be held to a higher standard when their models rely on data scraped without clear permission.


Filed under: SunoBreach, AIDataLeak, MusicAI, HaveIBeenPwned, DataPrivacy

Comments