Security

Suno data leak affects 55 million accounts worldwide

3 min read
Smartphone screen with the Suno logo and a security warning, in the background a laptop with lines of a database full of email addresses Image generated with GPT Image 2
Smartphone screen with the Suno logo and a security warning, in the background a laptop with lines of a database full of email addresses

TL;DR Too Long; Didn’t read

The service Have I Been Pwned registered the Suno data theft from November 2025 on July 20, 2026, with 55.3 million affected email addresses. In addition to names and addresses, phone numbers and parts of payment data are also exposed. Suno describes the incident to the media as limited and denies that sensitive data is affected. A targeted notification of users is not known so far.

Key takeaways

  • Have I Been Pwned confirms 55.3 million affected email addresses from the Suno data leak.
  • Tens of thousands of Stripe records contain names, addresses, and parts of payment card data.
  • Suno describes the incident to the media as limited and denies the loss of sensitive data.
  • The breach dates back to November 2025 and is related to the malware Shai-Hulud.
  • Suno deemed individual user notifications unnecessary based on its own assessment of the limited scope.
  • Suno has not yet disclosed how many affected accounts belong to users in the EU.

The security service Have I Been Pwned has added the data theft that began in November 2025 at the AI music service Suno to its database on July 20, 2026. According to this, 55.3 million unique email addresses are affected, significantly more than previously known. Suno describes the incident as limited and denies to the media that sensitive data was disclosed.

Have I Been Pwned database lists a far higher number of victims

Have I Been Pwned has listed the incident in its public database since July 20, 2026, making it fully verifiable for the first time. According to the service, the dataset contains more than 55.3 million unique email addresses as well as tens of thousands of records from the payment provider Stripe, including names, addresses, purchase amounts, and parts of card data – card type, expiration date, and last four digits. Complete card numbers are not included, according to Have I Been Pwned, since Suno itself has no access to that data at Stripe. The new figure far exceeds the previously known numbers for affected customers.

The underlying breach dates back to November 2025 and is the same incident Beckmann.ai previously reported on in connection with leaked Suno source code. What’s new is the total number of affected accounts, now publicly accessible through the Have I Been Pwned portal, which quantifies the actual scale of the leak for the first time and goes far beyond earlier estimates of several hundred thousand affected individuals. Anyone who wants to check whether their address is affected can do so directly via the service’s search function.

Suno disputes the actual scale

Suno told 404 Media that it detected the security incident in November 2025 and contained it quickly. The company emphasizes that no sensitive personal data was compromised, which is why individual user notifications were not required under applicable data protection law. Suno also points out that the attack affected outdated source code no longer in use and classifies the incident overall as limited.

This account stands in stark contrast to the data classes listed by Have I Been Pwned: names, addresses, phone numbers, purchase histories, and parts of payment data are generally considered sensitive personal information. Suno has not yet issued a public statement resolving the contradiction between its own classification and the data classes confirmed by Have I Been Pwned. Anyone with a Suno account can check via the Have I Been Pwned website whether their email address is included in the dataset, and should proactively change their password and watch for unusual login attempts or phishing emails that could draw on the stolen contact data.

Incident traces back to the Shai-Hulud attack from November

Access to the systems was reportedly gained by a person using the handle “ellie.191” via the malware Shai-Hulud, which spreads through compromised npm packages and had already hit several technology companies in recent months. The same access previously led to source code becoming public in mid-July, which according to 404 Media showed how Suno allegedly collected millions of clips from YouTube Music, Deezer, and other platforms to train its AI models – a story Beckmann.ai covered in detail at the time.

The case is also likely to touch the ongoing copyright lawsuits against Suno from Universal Music Group, Sony Music, and the label Jamendo, in which the leaked code is already being discussed as possible evidence. Suno did not disclose how many of the now-confirmed 55.3 million accounts belong to users in the European Union. That leaves it unclear to what extent European data protection authorities might get involved, and whether a cross-border inquiry under EU law will be opened at all.

What remains open is whether EU regulators will view a missed reporting obligation under the GDPR, given the now publicly confirmed numbers, should a significant share of European accounts turn out to be affected. Also crucial is whether Suno responds publicly to the contradiction between its own “limited incident” framing and the data volume confirmed by Have I Been Pwned.

Frequently asked questions

How can I check if my Suno account is affected?

Through the Have I Been Pwned website, you can check your email address against the published list of affected accounts. The Suno dataset has been available there since July 20, 2026.

Were complete credit card numbers stolen?

No, according to Have I Been Pwned, the dataset only contained card type, expiration date, and the last four digits from Stripe payment records, not complete card numbers.

Why didn't Suno inform users directly?

The company stated that it considered individual notifications unnecessary due to the limited scope of affected customer data based on its own assessment.

Is this data leak related to the copyright lawsuits against Suno?

Yes, the same breach already revealed internal source code in July 2026, which according to 404 Media documents the scraping of YouTube, Deezer, and other platforms and could play a role in the lawsuits from Universal Music Group and Sony Music.

What is the malware Shai-Hulud?

Shai-Hulud is malware that spreads through compromised npm packages and had already hit several technology companies in recent months before it was also used against Suno.


← Back to the blog