According to the data breach notification service Have I Been Pwned, the AI music generator Suno was recently attacked in November 2025, resulting in the leakage of personal information of more than 55.3 million users. The stolen sensitive data includes customer names, actual and email addresses, phone numbers, purchase records, as well as partial credit card numbers and expiration dates extracted from Stripe accounts.

Guitar Music AI Painting (1)

Although this security incident occurred several months ago and was recently exposed by media outlets such as 404Media, Suno had not previously proactively notified affected users or publicly disclosed the details. A company spokesperson, Rachel Racusen, later confirmed the existence of the security incident in November 2025 and did not deny the scale of affected individuals.

More critically, the leaked dataset also included Suno's source code, directly exposing the company's operations of scraping millions of songs and lyrics from well-known platforms such as Deezer, Genius, and YouTube to train its AI model.

Currently, Suno is facing a joint lawsuit from several major record companies, accused of copyright infringement due to large-scale scraping of copyrighted works. This security and data breach incident not only reveals shortcomings in user data protection in consumer-level AI applications, but the disclosed source code may also provide key evidence for legal accountability regarding the compliance and data sources of generative AI training, further increasing regulatory and compliance risks in this field.