AI music platform Suno breach exposes 55 million user accounts (2026)
A breach at AI music generator Suno, made public in July 2026 via 404 Media and Have I Been Pwned, exposed more than 55 million user records.
- Victim
- Suno
- records
- 55.3M
On 21 July 2026, the intrusion at Suno β the Cambridge, Massachusetts-based generative artificial-intelligence music platform β became public after the independent outlet 404 Media reported on a stolen dataset and the breach-notification service Have I Been Pwned loaded it. The dataset contained more than 55.3 million unique email addresses, making it one of the larger consumer data exposures disclosed during the month.
What happened
According to the reporting, the compromise itself occurred in November 2025, but Suno did not disclose its scope at the time. A hacker using the handle ellie.191 told 404 Media they had gained access by stealing a single employee's login credentials and then used that access to reach the company's outdated source code and a customer database. The stolen records reportedly included customers' names, physical and email addresses, phone numbers, purchase histories, and partial payment card details β including expiry dates β drawn from Suno's Stripe account.
Beyond customer data, the leaked source code allegedly documented how Suno assembled its training material, referencing scraping from streaming and stock-audio services and from podcast RSS feeds β a sensitive disclosure for a company already facing legal scrutiny over how its models were trained.
Suno's response
Suno characterised the November 2025 incident as limited and stated that "no sensitive personal information was compromised" β a claim that sits uneasily against the volume of names, contact details, and partial payment data found in the leaked dataset. The gap between that characterisation and the exposed records drew criticism from security researchers and prompted class-action interest.
Why it matters
The Suno case illustrates a recurring failure mode at fast-growing AI companies: a single set of stolen employee credentials, combined with legacy source code and a large accumulated customer database, was enough to expose tens of millions of records. It also underscores how breach-notification services and investigative reporting β rather than the breached company itself β increasingly drive public accountability when an organisation downplays an incident.
Timeline
A hacker using the handle 'ellie.191' compromises Suno's systems using stolen employee credentials and exfiltrates a customer database and internal source code.
The breach becomes public through reporting by 404 Media, and Have I Been Pwned loads the dataset, flagging more than 55 million affected accounts.
Sources
- techcrunch.comhttps://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/
- cybernews.comhttps://cybernews.com/security/data-breach-at-suno-affects-over-55-million-users/
- cyberinsider.comhttps://cyberinsider.com/data-breach-at-ai-music-service-suno-exposed-55-million-accounts/
- technadu.comhttps://www.technadu.com/suno-data-breach-55-million-emails-and-stripe-records-exposed/631566/
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Suno