AI music generation platform Suno has experienced a data breach that leaked the personal details of over 55 million users.
Cambridge, Massachusetts-based Suno claims it is building a future where everyone can make music. Over 100 million people have used Suno since it launched in 2023, with 2 million being paying subscribers. The company reports annual revenue of over $300 million from recurring customer subscriptions.
Suno AI music generative platform leaks customer data
The data breach leaked users’ email addresses and phone numbers, where they were provided during the signup process. It also leaked tens of thousands of Stripe records, including names, physical addresses, purchase amounts, and partial credit card information, such as card type, expiry date, and the last four digits of credit card numbers. Suno says it does not have access to customers’ full credit card details.
While not particularly sensitive, the leaked information could enable hackers to create convincing phishing messages targeting the affected individuals, luring them into disclosing more sensitive details such as credit card numbers. Purchase records make phishing emails more convincing by referencing real transactions, item IDs, and amounts, thereby increasing the likelihood that recipients will disclose their credit card details.
Consequently, affected users should be on the lookout for unsolicited messages purporting to originate from the company. They should also avoid clicking links from unfamiliar sources or downloading email attachments from unsolicited or suspicious messages, as these may contain malware or redirect them to fraudulent websites designed to harvest their sensitive information.
Meanwhile, data breach tracking website Have I Been Pwned estimated that the leak affected 55.3 million based on the number of unique email addresses.
So far, Suno has not acknowledged the data breach or attributed the cyber attack to any threat actor. The attack vector exploited also remains a mystery, and the AI music generation company has not disclosed receiving any ransom demands.
“When the disclosed scope of a breach grows this significantly in such a short period, it suggests that either the initial investigation was rushed or the organization lacked adequate visibility into its environment,” said Seemant Sehgal, Founder & CEO, BreachLock. “The scale and variety of the exposed data raise serious questions about internal segmentation, security monitoring and incident readiness. Regulators and customers will spend less time focused on the 55.3 million figure than on what Suno knew, when it knew it and how it responded. Organizations that cannot establish what was accessed, when and from where within the first 72 hours will find their disclosure decisions harder to defend than the breach itself.”
AI music controversy amplified in Suno data breach
The data breach also leaked source code dating between 2023 and 2024, showing Suno scraping music from various services, including YouTube, Deezer, Freesound, Genius, Pond5, Jamendo, the International Music Score Library Project, RSS feeds, and podcasts. The company admitted that it trained its AI tool using copyrighted music, claiming the practice falls under fair use.
Meanwhile, major record labels, including Sony Music Entertainment, UMG Recordings, and Warner Records, have complained about mass data scraping by AI companies. The Recording Industry Association of America (RIAA) also sued AI songmaking platforms Suno and Udio for reportedly scraping music without permission from copyright holders.
Nevertheless, Warner has settled the lawsuit with Suno and partnered with the AI music-generating platform, while other lawsuits remain pending in court.
Stable Audio (Stability AI) and Suno rival Udio have also faced legal disputes over scraping copyrighted music, being accused of committing mass copyright infringement. The recording companies argue that the AI music-generating platforms will cheapen and ultimately replace human artists, essentially wiping out years of investment.
They also allege that AI music generation tool users have been able to recreate elements of certain popular hits, including Mariah Carey’s “All I Want for Christmas Is You.” They also claimed that AI music-generating tool users could recreate hits indistinguishable from various popular musicians, essentially impersonating them.
While deepfakes have traditionally been associated with manipulated videos and cloned speech, the same technology is increasingly affecting the music industry. Modern AI music generators, such as Suno, Udio, and Stability AI, apparently enable users to recreate songs that imitate the voices and artistic styles of well-known musicians, blurring the line between authentic and AI-generated content and raising concerns about fraud, misinformation, and copyright infringement.
“The AI component is not necessarily the central issue here,” said Steven Swift, Managing Director, Suzu Labs. “There has been no public evidence directly attributing Suno’s security posture to its use of AI-generated code. However, rapidly growing AI companies may rely heavily on AI-assisted development, which can introduce security weaknesses when code is deployed without proper review and testing.”
“Most breaches result from organizations failing to follow established security practices. Companies using AI in their applications, automation and infrastructure need a comprehensive security baseline and regular testing to confirm that their controls work. That should include at least annual penetration testing of hosted applications, services, internal networks and devices,” advised Swift.

