Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Hacker Breach Exposes How AI Music Company Suno Scraped Songs From YouTube, Deezer and Genius

A hacker broke into AI music generator Suno's internal systems in November 2025 and pulled source code that reportedly maps out how the company built its training data, according to 404 Media. Suno confirmed the breach happened but says the exposed code is old and no longer used.
The hacker told 404 Media they got in by hitting a Suno employee with a worm, which gave them access to credentials for GitHub and cloud storage. From there they pulled source code plus what's described as a customer list covering hundreds of thousands of users, including email addresses and phone numbers.
Data provided to 404 Media shows Suno pulled music and lyrics from YouTube Music, Deezer and Genius, plus stock music libraries. The company reportedly used proxy services to grab material off YouTube, including acapella tracks. RSS feeds were apparently used to vacuum up hundreds of thousands of podcasts too.
None of this is shocking on its own. Suno already admitted in a 2024 court filing that its systems scraped "tens of millions of recordings" from the internet for training. The company's legal argument has always been that this counts as fair use under copyright law. What the hack adds is specificity: which platforms, which methods, and the scale of a system built to hoover up copyrighted work without asking permission first.
Suno is currently facing a copyright infringement lawsuit from major record labels in the U.S. Warner Music Group dropped out of that suit late last year after striking its own licensing deal with Suno, according to Engadget. Universal Music Group and Sony Music are still in it, as far as public reporting shows.
A Suno spokesperson gave 404 Media a statement standing by the company's public position: "Suno's AI models have been trained on publicly available music files and related metadata accessible on third-party websites on the open Internet." The spokesperson said Suno investigated the November incident, confirmed it "primarily involved outdated source code that is no longer in use at Suno," and concluded "no sensitive personal information was compromised." The company also said it doesn't have access to customers' full credit card numbers through Stripe, and decided individual customer notifications weren't legally required given what it calls the limited nature of the exposed data.
If the facts hold up—outdated code, no financial data, no notification requirement under current privacy law—that's a defensible position. But email addresses and phone numbers for hundreds of thousands of people were reportedly accessed. Most people would call that sensitive, even if it doesn't meet a legal threshold for mandatory breach notification. Companies get to make that call, and regulators haven't stepped in to say otherwise, but the gap between "legally not required to tell you" and "you'd probably want to know" is exactly the kind of thing consumer privacy laws struggle to close.
On the copyright side, there's a legitimate argument on both ends. Suno's position, that scraping publicly accessible files for AI training constitutes fair use, is an actual legal theory being tested in federal court right now, not a dodge. Fair use has covered transformative uses of copyrighted material before. Whether training a generative AI model counts is genuinely unsettled law, and courts across multiple AI copyright cases have split on similar questions.
The artists' and labels' counterargument is just as straightforward: none of them agreed to have their work fed into a machine that competes with them, and Suno's own 2024 court admission that it scraped tens of millions of recordings undercuts any claim this was a handful of stray files. Warner Music Group apparently decided a licensing deal was better than fighting it out, which suggests at least one major label saw more value in getting paid than in winning a fair-use argument outright.
No government agency has announced an investigation into the breach itself. No charges have been filed against Suno or the hacker. The lawsuit from Universal and Sony continues, and the hacked source code, if authenticated and entered into that litigation, could become evidence either side uses to argue their case. For now it's public reporting, a company statement, and an unresolved copyright fight that predates the hack by at least two years.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.