RSS
TwitterFacebook

Suno Data Breach Exposes Information of 55 Million Users Featured

The AI music platform breach reportedly exposed email addresses and, for some users, names, telephone numbers, addresses, purchase records, and partial payment-card information.

Suno Data Breach Investigation

Suno, Inc. operates an artificial intelligence platform that allows users to create music. In November 2025, the company experienced a security incident involving its systems.

The incident became widely known in July 2026. Have I Been Pwned later reported that the compromised data contained approximately 55.3 million unique email addresses connected to Suno accounts.

What Happened in the Suno Data Breach?

According to public reports, an unauthorized person obtained access to Suno source code and customer information. Some of the source code reportedly dated from 2023 and 2024.

Suno confirmed that it discovered a security incident in November 2025. The company said it quickly contained the incident. It also described the affected source code as outdated and no longer in use.

However, information reviewed by Have I Been Pwned reportedly contained data associated with millions of Suno users. In addition, the compromised records included some customer purchase information.

What Information Was Involved?

The information exposed was not the same for every user. According to Have I Been Pwned, the compromised data included:

  • Email addresses
  • Names
  • Telephone numbers
  • Physical addresses
  • Purchase information
  • Partial payment-card information

Most affected records contained an email address. Telephone numbers were included when users registered with a phone number.

The breach also reportedly involved tens of thousands of Stripe purchase records. Those records may have contained names, addresses, purchase amounts, card types, expiration dates, and the last four digits of payment-card numbers.

Complete payment-card numbers were not reported as exposed.

Who May Have Been Affected?

People who created or maintained a Suno account before or during November 2025 may have been affected.

Users who purchased a Suno subscription or another paid service may have had additional information exposed. For example, their records may have included purchase details or partial payment-card information.

However, not every affected user had the same information involved. The type of information exposed depended on how the person registered and whether the person made a purchase.

What Are the Potential Risks?

Personal information exposed in a data breach may be used for fraud or identity theft. It can also help criminals create convincing phishing messages.

For example, affected users may receive emails, text messages, or telephone calls that appear to come from Suno, Stripe, a bank, or a payment-card company.

Therefore, users should be cautious about unexpected messages. They should not click suspicious links or provide passwords, verification codes, or financial information in response to unsolicited communications.

What Should Affected Individuals Do?

Suno users should review their financial accounts and payment-card statements for unfamiliar activity.

They should also consider changing their Suno password. In addition, any password used for both Suno and another service should be replaced with a unique password.

Although passwords were not identified as part of the compromised dataset, unique passwords can reduce the risk of account takeover. Users should also enable multi-factor authentication wherever it is available.

Finally, affected individuals should keep copies of any breach notice, suspicious message, fraudulent charge, or related expense.

Suno Data Breach Legal Investigation

Attorneys are investigating the Suno data breach. The investigation will examine how the incident occurred, what information was exposed, and whether affected users may have legal claims.

If you had a Suno account before or during November 2025, your personal information may have been involved.

Please complete the form below to assist the investigation. There is no cost or obligation to submit the form. The information you provide will help determine how users were affected and what legal options may be available.


Tags:        

Leave a Reply

Your email address will not be published. Required fields are marked *