Suno is dealing with a breach affecting 55 million users
Suno suffered a breach affecting 55.3 million accounts, but the number only became public around eight months after the November 2025 attack. The real tension is not just the size. Suno had described the incident as involving old source code and no sensitive personal information, while the dataset later listed by Have I Been Pwned included emails, phone numbers and tens of thousands of Stripe purchase records.
AI music generator Suno breach affects 55M users, per Have I Been Pwned https://t.co/A7g8cJELv5
— TechCrunch (@TechCrunch) July 21, 2026
Q1What actually happened?
According to the Have I Been Pwned breach listing, hackers obtained data tied to 55.3 million Suno accounts during an attack in November 2025. Most records contained email addresses. Phone numbers were included when people had used them to register, and a smaller set contained purchase information from Stripe.
Q2What kind of payment information was exposed?
The dataset reportedly contained tens of thousands of Stripe purchase records with customer names, physical addresses, purchase amounts, card types, expiration dates and the final four digits of card numbers. Full card numbers were not reported. That makes this more serious than a basic email dump, even if attackers cannot directly charge a card using those details alone.
Q3Why is the timing important?
The attack happened in November 2025, but HIBP added the dataset in July 2026. That is roughly eight months later. Suno had already acknowledged that hackers accessed old source code, but said no sensitive personal information had been compromised. The new listing creates a direct tension between that earlier description and the data later found in the breach.
Q4How large is 55 million users?
It puts the incident firmly in mega-breach territory. It is almost ten times the 5.7 million customer records exposed in the Qantas breach, although it remains far below the 192.7 million people affected by the Change Healthcare attack. For a company founded only a few years ago, 55 million exposed accounts also shows how quickly consumer AI apps can build internet-platform-sized databases.
Q5Why does this hit Suno particularly hard?
Suno was already under pressure over how it trained its music models. Files from the same broader hack reportedly showed systems used to collect millions of music and lyric files from services including YouTube Music, Deezer and Genius. So one security incident has now created two problems at once: evidence for the copyright fight and a major consumer privacy issue.
Q6What is the bigger signal?
Consumer AI companies are reaching huge scale before their security and disclosure systems look ready for it. Suno was valued at $2.45 billion after raising $250 million in late 2025, yet an attack from that same period appears to have exposed data tied to tens of millions of accounts. The bottleneck is no longer just making impressive AI. It is protecting the giant user databases those products create.
Q7So should users be worried?
Yes, but the risk is mostly follow-on fraud rather than someone directly emptying a bank account. Leaked emails, phone numbers, addresses and purchase details can make phishing messages much more convincing. Suno users should be especially careful with messages claiming to concern subscriptions, refunds, payment failures or account verification, and should avoid reusing their Suno password elsewhere.
