Photo Credit: Sasun Bughdaryan

A Suno security breach last year allowed a hacker to steal the personal information of over 55 million people, including names, addresses, and more.

Last year, AI music generator Suno was the subject of a cyberattack, enabling a hacker to steal the personal information of over 55.3 million people, according to Have I Been Pwned, the data breach notification service. The breach took place in November 2025, but was only recently revealed by 404 Media.

The stolen data included customer names, physical addresses, email addresses, phone numbers, purchase history, and partial payment card numbers taken from the company’s Stripe account, which included card expiration dates.

“The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method,” reported Have I Been Pwned. “Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data, including the card type, expiry date, and last 4 digits.”

Suno advised Have I Been Pwned that it “does not have access to customers’ full credit card numbers in Stripe.” The data breach notification service advised affected users to change their passwords and enable two-factor authentication where available to add an extra layer of security to their accounts.

The theft also included Suno’s source code, which exposed the extent of data scraping from music streaming services and lyric sites, including YouTube, Deezer, and Genius, used to train Suno’s AI models. A group of major record labels is actively suing Suno with allegations that its data scraping did not constitute fair use and violated copyright law.

The hacked information includes source code that appears to be from 2023 to 2024. This code includes mention of “2,013,545 music clips,” “113,879 hours of youtube_music,” “17,615 hours of genius_hq,” “12,287 hours of deezer,” and only “410 hours of free sound.” This, as 404 Media points out, amounts to “at least decades’ worth of music.”

Meanwhile, Suno has neither publicly disclosed the breach nor notified affected users that their information was exposed. It wasn’t until TechCrunch’s coverage—and only after the story was published—that a Suno spokesperson responded, confirming that the company experienced a security incident in November. The spokesperson did not dispute the number of users affected.