A cyberattack at AI music generator Suno final 12 months allowed a hacker to steal the non-public data of greater than 55.3 million folks, in accordance with the information breach notification service Have I Been Pwned, providing the primary glimpse into the size of the information theft.
Per Have I Been Pwned, which obtained a duplicate of the breached dataset, the stolen information included prospects’ names, bodily addresses and electronic mail addresses, telephone numbers, purchases, and partial fee card numbers taken from the corporate’s Stripe account, together with card expiry dates.
The breach occurred in November 2025, however was solely lately revealed because of reporting by unbiased information outlet 404 Media.
The info theft additionally included Suno’s supply code, which revealed how the corporate allegedly scraped thousands and thousands of songs and lyrics from standard streaming websites, together with Deezer, Genius, and YouTube, to coach its AI fashions. A number of main file labels are currently suing Suno, claiming that its mass-scraping efforts violate copyright legislation.
Suno has not but publicly disclosed the cyberattack, or notified people that their data was taken. Suno co-founder Mikey Shulman didn’t reply to TechCrunch’s request for remark concerning the incident.
After publication, Suno spokesperson Rachel Racusen didn’t dispute the variety of customers affected, and confirmed that the corporate skilled a safety incident in November 2025. It’s not clear why the corporate has not but publicly acknowledged the information breach on its web site. Nor did the corporate present TechCrunch, when requested, with any communication the corporate might have despatched to customers informing them of a knowledge breach.
Up to date with remark from Suno.

