Suno scrapes millions of songs from YouTube, Genius, and Deezer

Leaked internal files reveal that Suno scraped millions of songs from YouTube, Deezer, and Genius for AI training, contradicting past denials.

By Central
The data breach exposes Suno's extensive scraping of copyrighted music from multiple platforms.
Highlights
  • Suno scraped over two million YouTube Music clips for its AI training dataset.
  • The company used a third-party service, Bright Data, to scrape a cappella versions from YouTube.
  • Suno acknowledged a security breach in November 2025 but did not notify affected customers.

Leaked data from a security breach at Suno has revealed the full extent of the AI music generator’s training data pipeline, exposing that the company scraped millions of songs and lyrics from YouTube Music, Deezer, and Genius. The materials, obtained by 404 Media from a hacker known as “ellie.191,” include source code and internal scraping instructions that contradict Suno’s longstanding refusal to disclose the composition of its training datasets. This incident provides the clearest picture yet of what Suno has been taking from online platforms and how it has been obtaining that material.

What the Leaked Data Reveals About Suno’s Training Dataset

Internal files from 2023 and 2024 show that Suno’s scraping infrastructure targeted at least seven sources: YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and the International Music Score Library Project (IMSLP). A file for YouTube Music notes that Suno had consumed 2,013,545 YouTube Music clips at the time it was last updated. Datasets compiled by the company included hundreds of thousands of hours of YouTube Music, thousands of hours of Deezer and Genius, and hundreds of hours of Freesound and MuseScore lyrics. Additional code indicates Suno also sought to download roughly one million hours of podcasts via the PodcastIndex tool.

The leaked code further suggests that Suno used a third-party company called Bright Data to scrape music from YouTube, and that it searched specifically for a cappella versions of songs on the platform to source vocal-only audio. This aligns with an amendment filed by the Recording Industry Association of America (RIAA) last year, which alleges that Suno unlawfully circumvented YouTube’s copyright protections by “stream ripping” tracks from the platform.

Suno has been the subject of multiple lawsuits alleging the use of copyrighted materials to train its AI models. In a notable case filed by the RIAA in June 2024, Suno openly admitted that it trains on copyrighted materials, arguing that doing so from publicly available music files on the open internet is legally permitted under the fair use doctrine. The leaked data appears to corroborate the RIAA’s allegations of intentional stream ripping from YouTube.

In a statement to 404 Media, an unnamed Suno spokesperson said: “As we have stated in public filings and disclosures, Suno’s AI models have been trained on publicly available music files and related metadata accessible on third-party websites on the open Internet.” The company has consistently maintained this position, though the specific platforms and methods detailed in the leaked code had not been previously acknowledged.

Customer Data Exposed in the Security Incident

Beyond training data, the hacker also accessed Suno customer information, including email addresses, phone numbers, and Stripe payment details. Several customers contacted by 404 Media confirmed that they had signed up for the service and said that Suno never notified them about the breach. Suno acknowledged the incident in a statement, saying it became aware of a security breach in November 2025 and that the situation was quickly contained. The company maintains that no sensitive personal information was compromised and that it does not have access to customers’ full credit card numbers in Stripe, adding that individual notifications were not warranted under applicable privacy laws based on the limited nature of the information believed to be involved.

What This Means for Users and the Industry

This development carries two immediate implications for professionals and developers working with AI music tools. First, the transparency question: Suno’s training data has been a black box, and this leak confirms that the company’s models are built on a vast corpus of copyrighted commercial music, not just royalty-free or licensed content. Anyone using Suno for commercial projects should be aware that the legal status of the output remains uncertain and subject to ongoing litigation. Second, the security incident is a reminder that AI service providers handling sensitive creative data can also expose customer information. Users should evaluate whether their AI tools of choice have disclosed their data practices and security incident response protocols. The broader industry trend is clear: as AI music generation gains traction, the tension between scraping-based training and copyright law will only intensify, and the outcome of the RIAA case against Suno could set a precedent for the entire sector.

Share This Article