Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Suno Breach From November 2025 Exposed Data on 55 Million People, Company Still Hasn't Told Them

An AI music generator used by tens of millions of people got hacked in November 2025. Nearly nine months later, the company still hasn't told its customers.
Have I Been Pwned, the data breach notification service run by security researcher Troy Hunt, says a hacker stole personal information belonging to more than 55.3 million Suno users. The breach itself happened in November 2025, but the scale of it only came to light after independent outlet 404 Media reported on the incident.
The stolen data includes names, physical addresses, email addresses, phone numbers, purchase histories, and partial payment card numbers, according to Have I Been Pwned, which obtained a copy of the breached dataset. The card data came from Suno's Stripe account and included expiration dates.
Company Silence
Suno has not publicly disclosed the cyberattack. It has not notified individual users that their data was stolen. Co-founder Mikey Shulman did not respond to a request for comment from TechCrunch about the incident.
Most states have breach notification laws requiring companies to tell affected consumers within a specific window, often 30 to 60 days, once a breach involving personal data is confirmed. If Suno knew about this breach months ago and sat on it, that's a legal problem, not just a PR one. No regulator has announced an investigation into Suno over this breach, and no charges or enforcement action have been filed as of today.
The Bigger Problem: What Was Stolen
The hacker didn't just grab customer records. The stolen data also included Suno's source code, according to Have I Been Pwned's findings. That code allegedly reveals how the company scraped millions of songs and lyrics from streaming platforms including Deezer, Genius, and YouTube to train its AI models.
Major record labels are already suing Suno, arguing that its mass-scraping of copyrighted material violates copyright law. If the leaked source code substantiates how that scraping worked, it hands plaintiffs a roadmap they didn't have before. That's a separate legal exposure from the breach itself, and potentially a more expensive one.
What This Means for 55 Million People
Partial credit card numbers and expiration dates aren't enough on their own to commit fraud in most cases. But combined with names, addresses, phone numbers, and purchase history, this is exactly the kind of dataset that fuels targeted phishing campaigns. Scammers don't need your full card number if they know your name, address, and what you bought. That's enough to craft a convincing fake email from 'Suno support' asking you to verify your payment method.
Companies that get breached and disclose quickly give customers a chance to watch their accounts, freeze cards, or change passwords before scammers start using the data. Companies that stay quiet leave customers exposed with no warning. Suno's customers currently have no way of knowing, from the company itself, that any of this happened.
An Unresolved Question
404 Media broke this story independently, meaning Suno's own disclosure practices weren't what surfaced the breach. It took outside reporting and a breach-notification service cross-referencing a leaked dataset for the scale to become public.
The open question now is whether any state attorney general or federal regulator steps in, given the apparent gap between when the breach happened and when it became public knowledge. Have I Been Pwned's data gives affected users a way to check if their information was in the stolen set. Suno, as of today, still hasn't given them anything.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.