YYaaa News

Suno Data Breach Hits 55.3M Users|Names, Addresses, Cards Leaked — Source Code Confirms Deezer/Genius/YouTube Scraping

TL;DR

AI music generator Suno breached — 55.3M users' info leaked including cards; source code shows scraping songs from Deezer/Genius/YouTube for training.

Have I Been Pwned disclosed on July 21AI music generator Suno was breached last year, with a hacker stealing personal information on more than 55.3 million people. This is the biggest data event yet in the AI music generation spaceand the first look at Suno's user scale.

Stolen data — customers' names, physical addresses, email addresses, phone numbers, purchase history, and partial payment card numbers from Suno's Stripe account (including card expiration). Payment card exposure means cards are on SDN-list risk and need bulk reissue.

User scale verified — Suno has never publicly disclosed its user count. Prior fundraising materials cited "tens of millions" but no specific figure. 55.3M is the biggest verifiable user base in AI music generation to date.

The second piece stolen is source codewhich reveals how Suno allegedly scraped millions of songs and lyrics from popular streaming sites including Deezer, Genius, and YouTube to train its AI model. This point is central to Suno's ongoing defence against the RIAA + Universal Music + Sony Music + Warner Music class action (starting June 2025) — Suno has consistently claimed training data is legal and refused to disclose sources. The source-code leak directly substantiates plaintiff scraping allegations.

Legal fallout will be heavy — the RIAA suit is in discovery phase, and Suno has refused to hand over training data sources. If this source-code leak is entered into court records, Suno's prior defence collapses. Deezer just disclosed 50%+ of uploads are AI (see this batch) — Suno scraped Deezer to train AI, then AI drowned Deezer's pipeline — the loop closes.

Suno official response — has not confirmed the disclosure. Have I Been Pwned (run by Troy Hunt) has added 55.3M emails to its database. Users can check exposure there.

Timeline — the attack actually happened in 2025. Suno never publicly notified users. Have I Been Pwned obtained the dataset via hacker channels a year later. Failure to actively disclose already violates California CCPA and EU GDPR 72-hour breach notification dutiesadditional fines follow.

via TechCrunch
Suno 數據泄漏 5,530 萬用戶|含姓名地址支付卡與源碼,源碼揭示抓取 Deezer/Genius/YouTube 訓練模型