Were you recently affected by a data breach?

Suno Data Breach

AI music platform Suno suffered a data breach in November 2025 that exposed personal information for more than 55 million users, including names, emails, phone numbers, addresses, and partial payment card data. Suno has not publicly disclosed the incident or notified affected users.

Suno
Date of Breach: The breach reportedly occurred in November 2025 but was not publicly revealed until security researchers and journalists reported on it in July 2026.
CAU logo

Who was affected:

Clients of Suno

Impacted Data:

Names, email addresses, phone numbers, physical addresses, purchase records, and partial payment card details including card type, expiration date, and the last four digits

AI music generation company Suno reportedly suffered a significant data breach that exposed the personal information of tens of millions of users. According to the breach notification service Have I Been Pwned and independent reporting, a hacker gained unauthorized access to Suno’s systems and obtained a large volume of customer data along with portions of the company’s source code.

Companies that collect names, contact information, and payment-related data from millions of customers have a responsibility to secure that information. When a breach of this scale occurs, affected individuals deserve clear information about what happened and what they can do to protect themselves.

Suno’s Data Breach Investigation

Reporting from the independent outlet 404 Media first revealed in mid-July 2026 that Suno had been hacked, with a hacker sharing evidence of the intrusion that included both customer data and portions of the company’s internal source code. Days later, the data breach notification service Have I Been Pwned confirmed it had obtained and analyzed a copy of the breached dataset, determining that it contained more than 55.3 million unique email addresses tied to Suno accounts. According to Have I Been Pwned’s analysis, the underlying breach itself occurred in November 2025, meaning the exposed data sat in the hands of an unauthorized party for many months before the public became aware of it.

Have I Been Pwned reported that the compromised information included customer names, physical addresses, email addresses, and phone numbers, the latter present for accounts that used a phone number as their sign-up method. A smaller but still substantial subset of the data, described as tens of thousands of records, reportedly came from Suno’s Stripe payment processor and included purchase amounts along with partial credit card details such as card type, expiration date, and the last four digits of the card number. Suno stated that it does not have access to customers’ full credit card numbers through Stripe, meaning complete card numbers were not part of the exposed dataset.

Notably, as of the most recent reporting, Suno had not publicly acknowledged the breach on its own website, and reporters were unable to confirm that the company had sent any direct notification to affected users informing them that their information had been exposed. A company spokesperson reportedly confirmed to journalists that Suno experienced a security incident in November 2025 without disputing the scale of users affected, but did not provide evidence of a customer notification effort.

Data breaches involving companies that process large volumes of consumer payment and contact information are an increasingly common target for hackers, in part because a single successful intrusion can yield contact information, purchase history, and partial financial data all at once, all of which carry resale value on illicit markets. The combination of full names, physical addresses, phone numbers, and even partial card data is particularly useful to fraudsters because it can support convincing phishing and social engineering attempts, even when full card numbers are not exposed.

Most state data breach notification laws require companies to notify affected residents within a defined window after discovering that personal information has been compromised, precisely so that consumers can take protective steps before their information is misused. A months-long gap between when a breach reportedly occurred and when it becomes public, as appears to be the case here, can leave affected individuals unaware that they need to take any precautions at all. When a company has not yet issued its own notification, consumers are often left to learn about a breach involving their information only through news coverage or third-party breach-monitoring services rather than directly from the company that held their data.

Anyone who has used Suno’s AI music generation service, particularly anyone who made a purchase through the platform, should treat this report seriously even without having received a direct notice from the company. Because the exposed information includes contact details often used to verify identity, affected individuals should also be alert to follow-up phishing attempts that may reference Suno or claim to be resolving issues related to this incident.

When Did This Breach Occur?

According to Have I Been Pwned’s analysis of the breached dataset, the underlying security incident occurred in November 2025. The breach was not widely reported until July 2026, when 404 Media first published details of the hack and Have I Been Pwned subsequently confirmed the scope of the exposed data.

What Information Was Breached?

The exposed dataset reportedly includes more than 55.3 million unique email addresses, along with names, physical addresses, and phone numbers for accounts that used a phone number to sign up. A smaller subset of records tied to Stripe purchases also included purchase amounts and partial payment card data, including card type, expiration date, and the last four digits of the card number. Suno has stated it does not have access to customers’ complete card numbers.

What You Can Do

If you have used Suno’s AI music generation platform, consider taking the following steps:

  • Monitor your email accounts and financial statements for unusual activity or unfamiliar charges.
  • Be cautious of phishing emails, texts, or calls referencing Suno or claiming to resolve an account or payment issue.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) if you are concerned about identity theft.
  • Update your Suno account password and enable two-factor authentication if available.
  • Avoid reusing your Suno password on other accounts, and change it elsewhere if you have done so.
  • Check whether your email address appears in the breach using a reputable breach-monitoring service.

File a Data Breach Lawsuit Against Suno

If your personal information was exposed in the Suno data breach, you may have legal options available to you. Companies that fail to adequately protect customer data, or that delay notifying affected individuals after learning of a breach, can potentially be held accountable for the resulting harm.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: The breach reportedly occurred in November 2025 but was not publicly revealed until security researchers and journalists reported on it in July 2026.
Date of Breach: The incident occurred around June 12, 2026 and was confirmed to have affected personal data on July 14, 2026; reported to the Idaho Attorney General's Office on July 23, 2026
Date of Breach: Not publicly disclosed in detail; reported to the Vermont Attorney General's Office on July 27, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.