
AI music generator Suno was the subject of a cyberattack in November 2025 that exposed the personal details of millions of customers, as revealed by Have I Been Pwned and 404 Media.
The details:
According to Have I Been Pwned, the cyberattack enabled a hacker to steal the personal information of over 55 million people.
It reports that addresses were contained in the data, as were phone numbers if used as the sign-up method.
It adds: “Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits.”
Suno advised Have I Been Pwned that “it does not have access to customers’ full credit card numbers in Stripe.”
Training sources:
As covered by 404 Media, among the stolen files was Suno’s source code, which exposed how the company allegedly scraped data from services such as YouTube, Deezer, and Genius to train its AI model.
Suno’s response:
TechCrunch reports that Suno spokesperson Rachel Racusen has confirmed the November 2025 security incident, and did not dispute the reported number of users impacted.
Suno is yet to publicly acknowledge the data breach on its website, and though asked by TechCrunch did not provide any communication it may have sent to users informing them of the breach.
👋 Disclosures & Transparency Block
This story was written with information from Have You Been Pwned, 404 Media, and TechCrunch.
We covered it because it’s news of a data hack impacting Suno and its customers.












