• July 24, 2026

AI music-generation platform Suno has suffered a major data breach affecting more than 55 million accounts.

The incident occurred in November 2025 but only became public in July 2026. Have I Been Pwned obtained a copy of the exposed data and added 55.3 million affected accounts to its breach-notification service on 20 July 2026.

What information was exposed?

The compromised data reportedly contains more than 55 million unique email addresses, along with phone numbers belonging to users who registered using a mobile number.

A smaller part of the breach also included tens of thousands of Stripe purchase records containing:

  • Customer names
  • Physical addresses
  • Purchase amounts
  • Payment card type
  • Card expiry dates
  • The final four digits of payment cards

Suno has stressed that it does not have access to customers’ complete card numbers through Stripe, and full card details were not listed among the exposed information.

How did the breach happen?

Reports indicate that the attacker gained access to credentials belonging to a Suno employee during a supply-chain attack. This reportedly provided access to company source code, cloud services and customer information.

The stolen material also reportedly contained internal source code and documents relating to how Suno collected music and other audio content used to develop its artificial intelligence models.

Suno said it became aware of the incident in November 2025 and quickly contained it. The company described the incident as primarily involving outdated source code that was no longer being used.

Suno says no sensitive personal information was compromised

Suno has stated that it did not believe sensitive personal information had been compromised and determined that individual notifications were not required under the applicable privacy laws.

However, the data reviewed by Have I Been Pwned reportedly includes email addresses, phone numbers, names, physical addresses, purchasing information and partial payment-card details.

While partial card information cannot usually be used to make payments on its own, it can make fraudulent emails, calls and text messages appear considerably more convincing.

What are the risks to affected users?

The greatest immediate risk is likely to be targeted phishing and impersonation.

Attackers may use information from the breach to create messages that appear to relate to a genuine Suno account, subscription or previous purchase. A fraudulent message could include a user’s name, address or the final digits of a payment card to make it appear legitimate.

Affected users should be particularly cautious of messages claiming that:

  • A Suno payment has failed
  • A subscription needs to be renewed
  • An account must be verified
  • A refund is available
  • Payment information needs to be updated
  • Immediate action is required to prevent an account from being closed

Users should avoid following links in unexpected emails or text messages. Instead, access Suno by entering its address directly into a browser or using the official application.

What should Suno users do?

Anyone who has previously created a Suno account should remain alert for suspicious emails, calls and text messages.

Users should review their bank and card statements for unfamiliar activity and contact their payment provider immediately if they identify an unrecognised transaction.

Passwords were not listed by Have I Been Pwned among the information exposed in this incident. However, anyone who reused their Suno password on another service should replace it with a unique password as a precaution.

Multi-factor authentication should also be enabled on important services such as email, banking and payment accounts wherever it is available.

Why this breach matters

The Suno incident demonstrates how a single compromised employee account can potentially provide access to a much wider collection of company systems and information.

It also highlights the importance of organisations limiting employee permissions, protecting cloud-service credentials and closely monitoring unusual access to internal systems.

With information connected to more than 55 million accounts now included in Have I Been Pwned, Suno users should treat unexpected messages concerning their accounts or payments with caution.

Leave a Reply

Your email address will not be published. Required fields are marked *