The Daily
Menu
Tech

AI Music Platform Suno Faces Data Breach Affecting 55 Million Users

A security incident at AI music generator Suno has exposed the personal information of over 55 million users. The breach, which occurred in November 2025, also revealed internal data regarding the company's model training practices.

By Ada

The AI music generation platform Suno has confirmed that it experienced a significant security incident in November 2025, resulting in the unauthorized access of personal data belonging to approximately 55.3 million users. The scale of the breach was first identified by the data notification service Have I Been Pwned, which obtained a copy of the compromised dataset. Despite the incident occurring several months ago, the company had not previously issued a public disclosure regarding the theft.

Mikey Shulman, co-founder of Suno | Source: TechCrunch
Mikey Shulman, co-founder of Suno | Source: TechCrunch

According to the findings, the exposed information includes a broad range of sensitive user details, such as names, physical addresses, email addresses, and phone numbers. Furthermore, the breach compromised purchase histories and partial payment card information, including card expiration dates sourced from the company's integration with Stripe. While Suno spokesperson Rachel Racusen confirmed the occurrence of the security incident, the company has not provided documentation of notifications sent to affected users, nor has it explained the delay in public acknowledgment.

Beyond the impact on individual users, the breach has provided insight into the company's internal operations. The stolen data included Suno’s source code, which reportedly contains details regarding the platform's model training methodology. Specifically, the code suggests that the company utilized large-scale scraping of songs and lyrics from various streaming platforms and databases, including YouTube, Genius, and Deezer. This revelation arrives at a critical juncture for the company, as it is currently embroiled in litigation with major record labels that allege these data collection practices constitute a violation of copyright law.

The incident highlights the growing security challenges faced by generative AI startups as they scale their user bases and aggregate massive datasets. As Suno navigates both the fallout of this data exposure and ongoing legal scrutiny, the industry remains focused on the broader implications for data privacy and intellectual property rights in the AI sector. The lack of immediate public notification in this instance has prompted questions regarding corporate transparency and the standard protocols for handling security failures in the rapidly evolving artificial intelligence landscape.