Suno Data Breach: 55 Million Emails and Stripe Records Exposed
- Breach scale: Suno exposed over 55 million unique email addresses in a November 2025 data breach.
- Payment records: Tens of thousands of Stripe records containing partial credit card data were also compromised.
- Delayed disclosure: The incident surfaced publicly in July 2026, eight months after it occurred.
AI music generation platform Suno suffered a data breach in November 2025 that stayed under wraps until it came to light in July 2026. Breach notification service Have I Been Pwned (HIBP) added 55,282,226 unique email addresses to its database on July 20.
The attacker reportedly used the Shai-Hulud worm, a self-replicating npm supply-chain malware, to compromise a Suno employee's developer credentials, which gave access to private code repos and internal databases.
What Data Was Exposed in the Suno Hack
The number of exposed unique email addresses makes this one of the larger exposures tied to an AI platform to date. While it's a smaller slice of the overall haul, the breach also pulled in tens of thousands of Stripe records connected to real purchases.
According to HIBP, taken together, the compromised dataset spans:
- email addresses,
- names,
- phone numbers,
- physical addresses,
- purchase records,
- partial credit card data.
Stripe Payment Data in the Suno Breach
Stripe records held names, physical addresses, purchase amounts, and partial card details — card type, expiry date, and the last four digits. Suno has stated that it "does not have access to customers' full credit card numbers in Stripe," according to 404 Media, meaning complete card numbers may not have been part of what leaked.
That combination of contact info, location, and payment fragments raises the stakes for affected users.
Ongoing Copyright Litigation
The same data breach also exposed source code allegedly showing Suno scraped training data from streaming services (YouTube Music, Deezer, Genius), stock music libraries (Pond5, Jamendo, Freesound, the International Music Score Library Project), and podcasts via RSS feeds. This revelation feeds into the ongoing UMG/Sony copyright litigation against Suno.
The code also suggested that Suno was using PodcastIndex for podcasts and Bright Data proxies for YouTube, the publication said. Last month, researchers discovered free smart TV apps that embed Bright Data SDK to build an AI web-scraping proxy network.
Suno reportedly never notified affected users, characterizing it as a quickly contained "limited security incident" that exposed "outdated source code that is no longer in use," but it sent a training data disclosure required under California law.




