Skip to content
This week I recommend: Neural Frames
The AI Musicpreneur
AI Music News

Suno admits a 2025 breach exposed 55 million users' personal data

4 min read Published By Christopher Wieduwilt
Suno brand graphic reading Make any song you can imagine, from the AI music generator hit by a data breach exposing 55 million users
Image: Suno

Suno has confirmed a data breach from November 2025 that reportedly exposed the personal information of 55.3 million users. The scale came from breach-notification service Have I Been Pwned, which said it obtained the dataset and added the records to its database on July 20, 2026. This is the same hack that, a week earlier, exposed how Suno trains its models. The difference now is who got hurt: the paying users, not the labels.

What the Suno breach exposed

The dataset held more than 55 million unique email addresses, plus phone numbers where users had given them at sign-up. That alone is a phishing kit for anyone who buys the file.

A smaller slice went further. Tens of thousands of Stripe purchase records held customer names, physical addresses, purchase amounts, and partial card details, including the card type, expiry date, and last four digits. Suno says it does not have access to full credit card numbers in Stripe, which is true and also not the point. Names and home addresses tied to email accounts are enough to do real damage.

Have I Been Pwned told affected users to change their passwords and turn on two-factor authentication where they can. That advice is standard, and it is the only warning most Suno users will get.

Suno confirmed the incident, then went quiet

When independent outlet 404 Media first reported the breach on July 15, the hacker was described as reaching data on hundreds of thousands of Suno customers. Have I Been Pwned’s copy put the real number two orders of magnitude higher.

Suno spokesperson Rachel Racusen did not dispute the 55.3 million figure and confirmed the November 2025 incident, TechCrunch reported on July 21. The company had earlier said the incident was “quickly contained” and mostly involved “outdated source code that is no longer in use.”

No sensitive personal information was compromised.
— Suno spokesperson, on the November 2025 breach

That claim is hard to square with the file Have I Been Pwned is holding. Names, physical addresses, and partial card data are sensitive personal information by any normal reading. Suno concluded that individual breach notifications “were not warranted under applicable privacy laws,” has not acknowledged the breach on its website, and, per TechCrunch, did not provide any notice it sent to users. Some customers told 404 Media they were never told anything.

Why this matters if you make music with Suno

Suno spent two years fighting the majors over what it took to build its model. The RIAA v. Suno case is still live, with the labels seeking damages that could reach $9 billion. This breach is a separate problem, and for the people who actually use the tool, a more immediate one.

If you paid Suno, your email is now in a public breach index, and there is a real chance your name, address, and partial card data rode along. Change the password, turn on 2FA, and watch for phishing that pretends to come from Suno.

Frequently asked questions

How many users did the Suno data breach affect?

The dataset held by Have I Been Pwned contained more than 55 million unique email addresses, with reports putting the total at 55.3 million affected users. Phone numbers were also present where users had supplied them at sign-up.

What personal data did the Suno breach expose?

The bulk of the data was email addresses and phone numbers. A smaller set of tens of thousands of Stripe purchase records also held customer names, physical addresses, purchase amounts, and partial card details, including card type, expiry date, and the last four digits. Suno says it does not hold full credit card numbers.

Did Suno notify users about the 2025 data breach?

No. Suno decided that individual breach notifications were not warranted under applicable privacy laws and has not publicly acknowledged the incident on its website. Some affected customers told 404 Media they were never told their data was exposed.

How was the scale of the Suno breach revealed?

Breach-notification service Have I Been Pwned said it obtained a copy of the dataset and added the records to its database on July 20, 2026. Suno spokesperson Rachel Racusen did not dispute the 55.3 million figure and confirmed a November 2025 security incident to TechCrunch.

About the author

Photo of Christopher Wieduwilt

Christopher Wieduwilt

AI Music Educator & Journalist

Covering AI music tools, industry shifts, and news for music creators and professionals. Twice-weekly newsletter at aimusicpreneur.com.

Share this article

Free newsletter

The AI music tools & news worth your time — 2× a week, read by 2,000+ pros.