{"id":64296,"date":"2026-07-22T04:15:50","date_gmt":"2026-07-22T08:15:50","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=64296"},"modified":"2026-07-22T04:15:50","modified_gmt":"2026-07-22T08:15:50","slug":"suno-data-breach-55-million","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/suno-data-breach-55-million\/","title":{"rendered":"Suno breach exposes data of 55 million users"},"content":{"rendered":"<p>A cyberattack targeting AI music generator <a href=\"https:\/\/overcentral.com\/en\/suno-data-scraping-leak\/\" title=\"Suno scrapes millions of songs from YouTube, Genius, and Deezer\" data-iacss-internal=\"1\">Suno<\/a> in November 2025 resulted in the exposure of personal data belonging to more than 55.3 million users, according to <a href=\"https:\/\/overcentral.com\/en\/assuranceamerica-data-breach-exposes-6-9-million-drivers-license-numbers\/\" title=\"AssuranceAmerica Data Breach Exposes 6.9 Million Driver&apos;s License Numbers\" data-iacss-internal=\"1\">data breach<\/a> notification service <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Have I Been Pwned<\/a>. The breach, which came to light through reporting by independent news outlet <a href=\"https:\/\/www.404media.co\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">404 Media<\/a>, represents one of the larger consumer data thefts tied to an artificial intelligence company. Have I Been Pwned obtained a copy of the compromised dataset, providing the first detailed picture of what was taken.<\/p>\n<h2>What Data Was Stolen in the Suno Breach<\/h2>\n<p>The stolen records include names, physical addresses, email addresses, and phone numbers of users. The breach also compromised purchase information and partial payment card numbers stored in Suno\u2019s Stripe account, including card expiry dates. The inclusion of financial data, even in truncated form, elevates the risk for affected individuals, as partial card numbers combined with other personal identifiers can be used in targeted phishing and social engineering attacks. The total count of affected individuals stands at approximately 55.3 million.<\/p>\n<h2>Source Code Theft Reveals AI Training Practices<\/h2>\n<p>Beyond user data, the attacker exfiltrated Suno\u2019s source code. Analysis of that code revealed that the company scraped millions of songs and lyrics from popular streaming platforms, including Deezer, Genius, and YouTube, to train its AI music generation models. This detail is particularly significant given that several major record labels are currently pursuing copyright litigation against <a href=\"https:\/\/suno.com\/\" target=\"_blank\" rel=\"sponsored noopener noreferrer\" data-iacss-external=\"1\">Suno<\/a>, arguing that the company\u2019s mass-scraping activities constitute copyright infringement. The source code leak provides direct evidence of the data sources used for model training, which could factor into those legal proceedings.<\/p>\n<h2>Why Suno Did Not Publicly Disclose the Breach<\/h2>\n<p>Suno has yet to issue a public acknowledgment of the cyberattack on its website or notify affected individuals directly. Co-founder Mikey Shulman did not respond to requests for comment. After publication of the initial reporting, Suno spokesperson Rachel Racusen confirmed that the company experienced a security incident in November 2025 and did not dispute the 55.3 million figure. However, the company did not explain why it had not notified users or posted a public disclosure. The delay in notification runs counter to standard incident response best practices and, depending on the jurisdictions of affected users, may conflict with data breach notification laws such as the GDPR for <a href=\"https:\/\/overcentral.com\/en\/european-politician-hacked-pegasus-spyware\/\" title=\"European politician investigating spyware hacked with Pegasus\" data-iacss-internal=\"1\">European<\/a> users or state-level statutes in the U.S. that require timely disclosure.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Anyone who has used Suno should treat their data as compromised. The first step is to change the password used on the Suno account if it is reused elsewhere, and ensure that any other accounts sharing that same credential are updated with a unique, strong password generated by a zero-knowledge password manager. Enabling two-factor authentication on all accounts that support it is essential. Users should monitor financial accounts for unauthorized transactions, given that partial payment card data was exposed, and consider placing a fraud alert or credit freeze with the major credit bureaus if they have not already done so. Because email addresses and phone numbers were leaked, affected individuals should remain vigilant against targeted phishing messages that may reference Suno or the breach to appear credible. Using a reputable no-log VPN when connecting to public Wi-Fi networks adds a further layer of protection against interception of any sensitive activity during this period.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cyberattack targeting AI music generator Suno in November 2025 resulted in the exposure of personal data belonging to more than 55.3 million users, according to data breach notification service Have I Been Pwned. The breach, which came to light through reporting by independent news outlet 404 Media, represents one of the larger consumer data [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":83827,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64296.png","fifu_image_alt":"Suno breach exposes data of 55 million users","footnotes":""},"categories":[349],"tags":[],"class_list":["post-64296","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64296.png","fifu_image_alt":"Suno breach exposes data of 55 million users","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=64296"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64296\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/83827"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=64296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=64296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=64296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}