AI music generator Suno experienced a significant data breach in November 2025, compromising the personal information of over 55.3 million users. The breach, recently disclosed by data breach notification service Have I Been Pwned, included sensitive data such as names, physical addresses, email addresses, phone numbers, purchase histories, and partial payment card details, including expiration dates.
The breach also exposed Suno’s source code, revealing that the company allegedly scraped millions of songs and lyrics from popular streaming platforms like Deezer, Genius, and YouTube to train its AI models. This practice has led to ongoing lawsuits from major record labels, who claim that Suno’s data collection methods violate copyright laws.
Despite the severity of the breach, Suno has not publicly disclosed the incident or notified affected individuals. Co-founder Mikey Shulman has not responded to requests for comment regarding the breach.
This incident underscores the critical importance of robust cybersecurity measures, especially for companies handling vast amounts of user data. The exposure of Suno’s data collection practices also highlights the need for transparency and ethical considerations in AI model training. Users should remain vigilant about their personal information and monitor for any unauthorized activities.