Data Breaches

← Breach overview
Suno, Inc. logo

Suno, Inc.

suno.com
🎮Entertainment

Suno, Inc. is a company based in Cambridge, Massachusetts, that develops an AI music generation platform. This platform allows users to create music, including vocals and instrumentation, from text or audio prompts.

Key Takeaways

  • In November 2025, Suno experienced a data breach that exposed email addresses, names, phone numbers, physical addresses, purchase details, and partial credit card data for 55.3 million records.
  • The same hack also leaked internal source code confirming Suno scraped copyrighted music from YouTube Music, Deezer, and Genius for training data — while publicly arguing that training on copyrighted works is fair use.
  • This incident is part of a pattern of data breaches affecting companies in the same sector, with other music and education platforms also reporting significant exposures around the same time.
  • Individuals affected by this breach should be vigilant about phishing attempts and other scams that use their exposed personal and purchase information.

Breach Overview

In November 2025, Suno, Inc. suffered a data breach that affected 55.3 million records. The exposed data included email addresses, names, phone numbers (for those who used them to sign up), physical addresses, and details of purchases. Partial credit card data was also exposed, specifically the card type, expiry date, and the last four digits. Suno has publicly acknowledged this incident, stating that they do not have access to customers' full credit card numbers in Stripe. The breach was later confirmed by Have I Been Pwned in July 2026.

Exposed Data

Email addressesNamesPartial credit card dataPhone numbersPhysical addressesPurchases

Timeline & Cause

The data breach at Suno, Inc. occurred in November 2025. It was publicly disclosed on July 20, 2026. The specific cause or method of how the breach happened was not detailed in the provided information.

Next Steps

The exposed data, including names, email addresses, phone numbers, physical addresses, and purchase details, could be used by attackers to craft highly convincing phishing emails, text messages, or phone calls. These scams might impersonate Suno or other services to trick you into revealing more sensitive information or making fraudulent payments. Be extremely cautious of any unsolicited communications asking for personal details or directing you to suspicious websites. Since partial credit card data was exposed, monitor your bank and credit card statements for any unauthorized transactions, even though full card numbers were not revealed. If you notice any suspicious activity, contact your bank or credit card provider immediately.

Take Action