Suno breach exposed 55.3 million accounts and source code listing music scraping sources

Suno breach exposed 55.3 million accounts and source code listing music scraping sources

N
News Editor
2026-07-22 09:01:35
AI music platform Suno is facing a fresh wave of scrutiny after a newly indexed data breach revealed more than 55.3 million unique email addresses and tens of thousands of Stripe payment records. The breach, which Suno said stemmed from a November 2025 security incident, was added to Have I Been Pwned on July 20, according to founder Troy Hunt. If users signed up with phone numbers, those were included as well, and Hunt said 24% of the leaked emails had already appeared in the service’s existing breach database. The bigger problem for Suno may be the source code leaked alongside the user data. Code dated from 2023 to 2024 reportedly listed training data sources and volumes tied to YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, IMSLP and podcasts collected via RSS. 404 Media said the materials add up to more than 380,000 hours of audio and lyrics, including over 2 million YouTube Music clips. Those details track closely with the claims made in copyright lawsuits brought by Sony Music, UMG and Warner in 2024, though Warner later settled and entered a licensing partnership with Suno. Sony and UMG are still pressing their case.
Sunodata breachAI musiccopyright lawsuitsource code leakSony MusicUMGtechnology

Suno is under renewed pressure after a data breach tied to the AI music platform exposed more than 55.3 million unique email addresses, along with tens of thousands of Stripe payment records. The incident was only added to Have I Been Pwned on July 20, months after Suno said the security event took place in November 2025.

The account leak alone was serious. What raised the stakes was the source code released with it. The leaked code, dated from 2023 to 2024, reportedly spelled out where Suno gathered music and lyrics used for training, naming services including YouTube Music, Deezer and Genius. Those disclosures line up with the core claims now being pressed against the company by Sony Music and Universal Music Group.

HIBP entry lists 55.3 million unique emails

Have I Been Pwned founder Troy Hunt said in the listing notes that the Suno dataset contained more than 55.3 million unique email addresses. If users had registered with phone numbers, those were included as well.

Hunt also said 24% of the leaked emails had already appeared in HIBP’s existing breach corpus.

The breach data also included tens of thousands of Stripe records, according to the listing. Exposed fields covered names, physical addresses, purchase amounts, card brand, expiry date and the last four digits of card numbers. Suno said it could not access full card numbers through Stripe, which limited direct card fraud risk. Even so, a mix of names, addresses and purchase histories can be useful in phishing campaigns.

Suno confirmed a November 2025 security incident

Suno spokesperson Rachel Racusen did not dispute the reported number of affected users and confirmed the company experienced a security incident in November 2025. The company, however, has not posted a notice about the breach on its website, and the report said there was no record of users being notified.

404 Media was the outlet that first pushed the breach into public view. Suno acknowledged the incident afterward.

Leaked code listed scraping sources and volumes

For record labels, the exposed account data may be only part of the story. The source code released by the hacker reportedly laid out the sources and scale of Suno’s training materials in direct terms. Based on a list compiled by 404 Media, the leaked materials referenced not only YouTube Music, Deezer and Genius, but also Pond5, Jamendo, Freesound, the International Music Score Library Project, or IMSLP, and podcasts collected through RSS feeds.

The figures were detailed. YouTube Music alone was listed with 2,013,545 music clips totaling 113,879 hours. Another dataset marked as ytm_tagged was listed at 152,162 hours. Other sources included 62,117 hours from Pond5, 19,514 hours from IMSLP, 17,615 hours from Genius, 12,287 hours from Deezer and 3,726 hours from Jamendo.

Combined, the material exceeded 380,000 hours, roughly 43 years of nonstop audio. Folder names in the code reportedly included genius_hq, youtube_music, deezer and ytm_tagged.

The value of that list in litigation is obvious: it reduces the need to infer training inputs indirectly through audio fingerprinting, output analysis or expert testimony. For the past two years, record labels trying to show that AI systems had consumed their catalogues often needed to build those arguments through technical comparison and courtroom explanation.

Warner settled, Sony and UMG kept fighting

The legal fight began in 2024, when the Recording Industry Association of America, acting for Sony Music Entertainment, UMG Recordings and Warner Records, sued Suno and Udio over alleged large-scale use of copyrighted sound recordings to train AI models without authorization.

Suno’s defense has centered on fair use. In court filings, the company acknowledged using what it described as “basically all music files of reasonable quality that are accessible on the open Internet,” amounting to tens of millions of recordings.

The three plaintiffs later split paths. Warner Music Group reached a settlement with Suno on Nov. 25, 2025, and the two sides moved into a licensing partnership. Suno’s valuation later doubled to $5.4 billion. Sony and UMG chose to continue the case, and the two sides faced off this month in their first direct courtroom clash over whether the training qualified as fair use.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.