AI music generation company Suno reportedly suffered a significant data breach that exposed the personal information of tens of millions of users. According to the breach notification service Have I Been Pwned and independent reporting, a hacker gained unauthorized access to Suno’s systems and obtained a large volume of customer data along with portions of the company’s source code.
Companies that collect names, contact information, and payment-related data from millions of customers have a responsibility to secure that information. When a breach of this scale occurs, affected individuals deserve clear information about what happened and what they can do to protect themselves.
Suno’s Data Breach Investigation
Reporting from the independent outlet 404 Media first revealed in mid-July 2026 that Suno had been hacked, with a hacker sharing evidence of the intrusion that included both customer data and portions of the company’s internal source code. Days later, the data breach notification service Have I Been Pwned confirmed it had obtained and analyzed a copy of the breached dataset, determining that it contained more than 55.3 million unique email addresses tied to Suno accounts. According to Have I Been Pwned’s analysis, the underlying breach itself occurred in November 2025, meaning the exposed data sat in the hands of an unauthorized party for many months before the public became aware of it.
Have I Been Pwned reported that the compromised information included customer names, physical addresses, email addresses, and phone numbers, the latter present for accounts that used a phone number as their sign-up method. A smaller but still substantial subset of the data, described as tens of thousands of records, reportedly came from Suno’s Stripe payment processor and included purchase amounts along with partial credit card details such as card type, expiration date, and the last four digits of the card number. Suno stated that it does not have access to customers’ full credit card numbers through Stripe, meaning complete card numbers were not part of the exposed dataset.
Notably, as of the most recent reporting, Suno had not publicly acknowledged the breach on its own website, and reporters were unable to confirm that the company had sent any direct notification to affected users informing them that their information had been exposed. A company spokesperson reportedly confirmed to journalists that Suno experienced a security incident in November 2025 without disputing the scale of users affected, but did not provide evidence of a customer notification effort.
Data breaches involving companies that process large volumes of consumer payment and contact information are an increasingly common target for hackers, in part because a single successful intrusion can yield contact information, purchase history, and partial financial data all at once, all of which carry resale value on illicit markets. The combination of full names, physical addresses, phone numbers, and even partial card data is particularly useful to fraudsters because it can support convincing phishing and social engineering attempts, even when full card numbers are not exposed.
Most state data breach notification laws require companies to notify affected residents within a defined window after discovering that personal information has been compromised, precisely so that consumers can take protective steps before their information is misused. A months-long gap between when a breach reportedly occurred and when it becomes public, as appears to be the case here, can leave affected individuals unaware that they need to take any precautions at all. When a company has not yet issued its own notification, consumers are often left to learn about a breach involving their information only through news coverage or third-party breach-monitoring services rather than directly from the company that held their data.
Anyone who has used Suno’s AI music generation service, particularly anyone who made a purchase through the platform, should treat this report seriously even without having received a direct notice from the company. Because the exposed information includes contact details often used to verify identity, affected individuals should also be alert to follow-up phishing attempts that may reference Suno or claim to be resolving issues related to this incident.
When Did This Breach Occur?
According to Have I Been Pwned’s analysis of the breached dataset, the underlying security incident occurred in November 2025. The breach was not widely reported until July 2026, when 404 Media first published details of the hack and Have I Been Pwned subsequently confirmed the scope of the exposed data.
What Information Was Breached?
The exposed dataset reportedly includes more than 55.3 million unique email addresses, along with names, physical addresses, and phone numbers for accounts that used a phone number to sign up. A smaller subset of records tied to Stripe purchases also included purchase amounts and partial payment card data, including card type, expiration date, and the last four digits of the card number. Suno has stated it does not have access to customers’ complete card numbers.
What You Can Do
If you have used Suno’s AI music generation platform, consider taking the following steps:
- Monitor your email accounts and financial statements for unusual activity or unfamiliar charges.
- Be cautious of phishing emails, texts, or calls referencing Suno or claiming to resolve an account or payment issue.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) if you are concerned about identity theft.
- Update your Suno account password and enable two-factor authentication if available.
- Avoid reusing your Suno password on other accounts, and change it elsewhere if you have done so.
- Check whether your email address appears in the breach using a reputable breach-monitoring service.
File a Data Breach Lawsuit Against Suno
If your personal information was exposed in the Suno data breach, you may have legal options available to you. Companies that fail to adequately protect customer data, or that delay notifying affected individuals after learning of a breach, can potentially be held accountable for the resulting harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.