Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Suno Confirms November Breach That Exposed How It Scraped Songs From YouTube, Deezer and Genius

Since 404 Media first reported details of the Suno breach, the AI music company has confirmed the hack happened, but insists it's old news that doesn't affect anyone today.
Suno told 404 Media the intrusion occurred in November 2025 and was "quickly contained." The company says the exposed material involved "outdated source code that is no longer in use" and that "no sensitive personal information was compromised." Suno also says it doesn't have access to customers' full credit card numbers through Stripe, its payment processor.
According to 404 Media's reporting, a hacker used a worm to compromise a Suno employee's credentials, gaining access to the company's GitHub repositories and cloud services. That access reportedly handed over source code detailing Suno's AI training pipeline, plus a customer list covering hundreds of thousands of users, including email addresses and phone numbers.
How Suno Allegedly Built Its Training Data
The leaked source code reportedly lays out, in granular detail, where Suno's training data came from. According to 404 Media's review of the material, Suno scraped songs and lyrics from YouTube Music, Deezer and Genius, along with stock music libraries. The company allegedly used proxy services to pull tracks off YouTube, including acapella versions, and scraped hundreds of thousands of podcasts via RSS feeds.
None of this is a total shock. Suno already admitted in a 2024 court filing that its systems scraped "tens of millions of recordings" off the internet for training, arguing the practice qualifies as fair use under copyright law. The Atlantic reported last month on massive datasets of scraped songs used across the AI industry. The hack reportedly adds a specific, code-level account of Suno's methods, rather than the company's own characterization of them.
Suno is currently a defendant in a copyright infringement lawsuit brought by major record labels in the United States. Warner Music Group dropped out of that suit late last year after striking a licensing deal with Suno. The other labels' litigation continues.
The Customer Notification Question
Suno decided against notifying individual customers about the breach. The company told 404 Media that "based on the limited nature of the customer information believed to be involved," it determined "individual notifications were not warranted under applicable privacy laws."
That judgment call is one companies make constantly, and it's not automatically wrong. Email addresses and phone numbers, while not as sensitive as Social Security numbers or full payment card data, are still the kind of information that fuels phishing campaigns and spam. Whether skipping notification cleared the bar under state breach-notification laws depends on jurisdiction-specific thresholds that vary widely, and no regulator has publicly challenged Suno's call as of this writing.
The breach handed independent reporters a receipt for practices Suno had previously described only in its own carefully worded court filings and public statements. A company insisting its AI trains only on "publicly available music files and related metadata accessible on third-party websites on the open Internet" is a very different thing from source code allegedly showing proxy-based scraping of YouTube acapella tracks and mass podcast harvesting via RSS. Suno's framing treats those as the same thing. A reasonable copyright holder would not.
No new lawsuit or regulatory action has been announced specifically over the breach itself. The unresolved question is whether the leaked source code becomes evidence in the ongoing label litigation, where plaintiffs' attorneys would likely want an independent account of Suno's scraping methods rather than the company's own description of them in prior filings.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.