Troy Hunt’s Have I Been Pwned service has confirmed that a breach of AI music startup Suno compromised more than 55 million user accounts, marking one of the larger security incidents to hit an AI platform this year. The exposed data set includes email addresses as the primary dataset, with phone numbers appearing where users chose that sign-in method instead.
The compromised records extend into financial data as well. Thousands of Stripe payment entries leaked names, mailing addresses, purchase histories, and partial credit card details including the card brand, expiration date, and the final four digits of each card number.
Whoever claimed responsibility for the intrusion also shared source code reportedly dating from 2023 and 2024. The code allegedly shows Suno pulling millions of songs and lyrics from YouTube Music, Deezer, and Genius without permission to train its AI music generation models. Sunu has acknowledged scraping publicly available music but maintains the practice qualifies as fair use under copyright law.
Sony Music Entertainment, UMG Recordings, and Warner Records jointly sued Suno and competitor Udio in 2024 over those same scraping practices. The breach now raises deeper questions about how AI platforms protecting both customer data and the provenance of their training datasets.
