
A cyberattack against AI music generation platform Suno exposed the personal information of more than 55.3 million people, according to data breach notification service Have I Been Pwned, which obtained a copy of the stolen dataset and provided the first detailed look at the scope of the theft.
The breach occurred in November 2025 but did not come to light until independent outlet 404 Media reported on it last week, after the stolen data appeared online. The hacker, who goes by the name ellie.191, told 404 Media that access to Suno’s systems was gained by stealing the login credentials of a single employee.
Have I Been Pwned founder Troy Hunt said the exposed dataset contained 55.3 million unique email addresses along with tens of thousands of Stripe payment records. Hunt also identified names, phone numbers, purchase histories, physical addresses and partial credit card details, including card type, expiration date and the last four digits, among the compromised information. In a post on the social platform X, Hunt said 24 percent of the exposed email addresses had already appeared in the Have I Been Pwned database from previous breaches.
Using the stolen credentials, the attacker reached Suno’s outdated source code, which laid out methods for scraping songs and lyrics from platforms including YouTube Music, Deezer and Genius, along with stock music libraries Pond5, Jamendo and Freesound, the International Music Score Library Project, and podcasts pulled through RSS feeds. The intrusion also gave the hacker access to Suno’s customer records, which included email addresses, phone numbers and Stripe payment information.
Suno did not inform affected users when the breach took place. At the time, a company spokesperson said, "Based on the limited nature of the customer information believed to be involved, we determined that individual notifications were not warranted under applicable privacy laws." Suno has still not publicly disclosed the incident on its own channels. Suno co-founder and CEO Mikey Shulman did not respond to a request for comment from TechCrunch regarding the breach. After TechCrunch’s report was published, Suno spokesperson Rachel Racusen confirmed that the company had experienced a security incident in November 2025.
The exposed source code also detailed how Suno allegedly scraped millions of songs and lyrics from major streaming platforms to train its artificial intelligence models, a practice at the center of ongoing lawsuits filed against the company by several major record labels.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543