Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

haveibeenpwned+1podcastvideos+1404media+1The AI music generation platform Suno suffered a data breach in November 2025 that went undisclosed for eight months, with Have I Been Pwned adding more than 55 million unique email addresses to its database on July 20, 2026.haveibeenpwned+1
The compromise came to light on July 14 when 404 Media published an investigative report based on data shared by a hacker operating under the handle "ellie.191," who gained access to Suno's systems through a supply-chain compromise of employee credentials. The attacker reportedly exploited the Shai-Hulud worm, a self-replicating malware that targeted the npm ecosystem beginning in September 2025, harvesting developer credentials and spreading across hundreds of software packages.podcastvideos+4
According to Have I Been Pwned, the stolen data included over 55.3 million unique email addresses, phone numbers used for sign-up, and tens of thousands of Stripe purchase records containing names, physical addresses, purchase amounts, and partial credit card data including card type, expiry date, and last four digits. Suno advised that it "does not have access to customers' full credit card numbers in Stripe".haveibeenpwned
Suno did not notify affected users of the breach. The company characterized the event as a "limited security incident" involving "outdated source code," asserting that no "sensitive personal information" was compromised. Suno's position that notifications were "not warranted under applicable privacy laws" has drawn criticism, as typical U.S. breach-notification statutes require disclosure when personal data is exposed.podcastvideos
Troy Hunt, who operates Have I Been Pwned, confirmed on July 19 that data from the November 2025 breach had surfaced publicly the prior week.linkedin
Beyond customer data, the breach exposed internal source code that revealed Suno's training data practices — including the scraping of more than two million music clips from YouTube Music, tens of thousands of hours from Deezer and Genius, and content from stock music libraries and podcast feeds. The disclosure has added weight to ongoing copyright infringement litigation against Suno by major record labels, including Universal Music Group and Sony Music.youtube+1
The Shai-Hulud worm that enabled the breach had previously prompted a high-severity alert from India's Computer Emergency Response Team, which warned that the attack posed risks to startups, fintech platforms, and e-governance applications relying on npm-based software.linkedin