AI music platform Suno exposes 55M users in data breach
AI music platform Suno experienced a data breach, exposing 55 million user accounts. The incident, confirmed by Have I Been Pwned, detailed the scale of the compromise affecting its global user base. Proprietary user data from the AI music generation service was exfiltrated, impacting a significant portion of its subscribers. The full extent of the data loss remains under investigation.
Severity: Critical · Category: Data Exfiltration
Impact: 55 million user accounts from the AI music platform Suno were exposed in a data breach.
Source: The Register · Jul 21 2026 · Original source
What Happened
AI music generator platform Suno experienced a data breach that exposed more than 55 million user accounts. The scale of the breach was confirmed by Troy Hunt's Have I Been Pwned service after ingesting the compromised files. The data dump primarily consisted of user email addresses, along with phone numbers for users who had registered with them. Additionally, tens of thousands of Stripe records were revealed, containing sensitive information such as names, physical addresses, purchase amounts, and partial credit card data, including card type, expiry date, and the last four digits of the card number.
An individual claimed responsibility for breaching Suno and also provided source code, reportedly dating from 2023 and 2024. This source code allegedly demonstrated that Suno had been scraping millions of songs and lyrics from various services, including YouTube Music, Deezer, and Genius, for the purpose of training its AI models. Suno has previously acknowledged training its AI on music available on the open internet, asserting that such actions constitute fair use.
Timeline
- 2023 and 2024 — Source code supplied by the individual claiming responsibility for the breach dates from this period, allegedly showing Suno's scraping activities.
- 2024 — The Recording Industry Association of America (RIAA) sued Suno and rival Udio for allegedly scraping songs en masse without permission.
- November 2025 — Major record labels complained about mass data scraping and copyright infringement by AI companies prior to Suno's breach.
- Last week (relative to July 21, 2026) — News of the data breach 'slip-up' broke.
- July 21, 2026 — Troy Hunt's Have I Been Pwned service confirmed the scale of Suno's data breach for the first time.
Technical Analysis
The data breach resulted in the exposure of user account information, including email addresses and phone numbers, indicating a compromise of Suno's user database. The incident also involved the revelation of tens of thousands of Stripe records, which contained personal and financial details such as names, physical addresses, purchase amounts, and partial credit card data (card type, expiry date, and the last four digits of the card number). This suggests a compromise extending to payment processing records or systems integrated with Stripe.
The individual claiming responsibility for the breach provided source code, reportedly from 2023 and 2024, which allegedly detailed Suno's practice of scraping millions of songs and lyrics from services like YouTube Music, Deezer, and Genius to train its AI. This suggests that the breach may have involved access to internal development or operational systems, potentially revealing proprietary code and confirming controversial data acquisition methods.
Impact
The data breach exposed more than 55 million user accounts, compromising email addresses and phone numbers. Additionally, tens of thousands of Stripe records were revealed, containing sensitive user data such as names, physical addresses, purchase amounts, card type, expiry date, and the last four digits of the card number. This incident marked the first time the scale of Suno's data breach was publicly quantified.
Beyond the user data exposure, the individual claiming responsibility for the breach supplied source code that allegedly demonstrated Suno's practice of scraping millions of songs and lyrics from services including YouTube Music, Deezer, and Genius for AI training. This revelation impacts Suno's ongoing legal and ethical challenges, as the company has been sued by major record labels, including Sony Music Entertainment, UMG Recordings, and Warner Records, in 2024 for alleged mass scraping without permission. While Warner has since settled its litigation and formed a commercial partnership with Suno, Sony and UMG continue their claims in court.
How Fencio prevents this
Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.
Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.