Suno’s latest unwanted release is a data breach affecting more than 55 million accounts.
On July 20, 2026, Have I Been Pwned added the November 2025 breach to its database, revealing that 55.3 million unique accounts had been affected. The exposed dataset included email addresses, phone numbers, names, physical addresses, purchase records, and partial payment card details from Stripe.
The new listing gives users their clearest opportunity yet to check whether their information was compromised, months after Suno decided that individual customer notifications were not required.
Have I Been Pwned said the stolen dataset contained over 55 million unique email addresses. Phone numbers were also included when customers had used them instead of email addresses to register.
The breach also contained tens of thousands of Stripe purchase records with names, physical addresses, purchase amounts, card types, expiration dates, and the final four digits of payment cards. Full card numbers were not included because Suno did not have access to them through Stripe.
Suno confirmed that it experienced a security incident in November 2025. According to Gizmodo, a spokesperson described it as a “limited security incident that was quickly contained” and said it primarily involved outdated source code the company no longer used.
The company also stated, “No sensitive personal information was compromised.”
However, the combination of names, addresses, purchase histories, phone numbers, and partial card details could make phishing attempts appear more credible, particularly if attackers impersonate Suno, Stripe, or another payment provider.
Attackers do not always need passwords or full credit card numbers to cause harm. Personal and transaction data can help them make fraudulent emails, calls, or text messages appear legitimate.
Must-read security coverage
Suno did not send individual notifications
Suno told Gizmodo that it decided individual customer notifications were not warranted under applicable privacy laws because of the limited nature of the information it believed was involved.
TechCrunch reported that Suno had not publicly disclosed the breach on its website. The company confirmed the incident after the publication requested comment and did not dispute the figure of 55.3 million affected accounts.
The lack of individual alerts has practical consequences.
Users cannot review suspicious activity, change reused passwords, or watch for targeted scams when they do not know their information may have been taken.
The incident also highlights a broader compliance and risk-management issue for companies collecting customer and payment data. Organizations may determine that a breach does not meet a legal notification threshold, yet users can still face phishing and impersonation risks from the exposed information.
Stolen source code raised separate questions
The attacker also reportedly accessed Suno’s source code, which revealed details about how the AI music company collected material for model training. Engadget noted that the code referenced YouTube Music, Deezer, Genius, podcasts, and several stock music libraries.
Suno has argued that its models were trained on publicly available material and that using such content qualifies as fair use. Record labels have challenged those practices through copyright lawsuits, making the stolen source code relevant beyond the customer data exposure.
Affected users should now:
- Check their email address through Have I Been Pwned.
- Change any password reused across Suno and other services, and enable two-factor authentication where supported.
- Treat unexpected Suno, Stripe, or payment-related messages with caution.
The breach happened months ago, but the newly documented scale gives millions of account holders information they did not previously have and a reason to review their security now.
See the biggest data breaches of 2026 so far, ranked by impact, including what was exposed, who was affected, and what to do next.
Read the full article here