Suno account leaked personal data from 55.3 million records; the hacker conveniently dumped “evidence of infringement” to the record label

AI music platform Suno was hacked in November 2025. While the leak exposed 55.30 million users’ email addresses and tens of thousands of Stripe payment records, the incident was only added to Have I Been Pwned on July 20 of this year. To make matters worse, the hackers also dumped the original source code from 2023 to 2024, which clearly states that Suno sourced and scraped more than 380,000 hours of music and lyrics from places such as YouTube Music, Deezer, and Genius—this is exactly the core accusation Sony Music and UMG are making against it right now.
(Background: Sony sues Suno with a court hearing this month—does using AI to train on copyrighted songs count as “fair use,” the first time it’s argued in court?)
(Additional context: AI music startup Suno’s valuation doubled in half a year to reach $5.4 billion, and after settlement agreements and licensing deals with Warner are signed, it will roll out new products.)

An account leak on its own is already bad enough; what’s truly fatal is the batch of source code the hackers conveniently attached as well.

The intrusion took place in November 2025, but the information only came to light eight months later. On July 20, the cybersecurity notification service Have I Been Pwned added a Suno entry. In a login description, founder Troy Hunt pointed out that this dataset contains more than 55.30 million unique email addresses, and if users originally registered with phone numbers, those phone numbers were included too. Troy Hunt also noted that 24% of the emails had already appeared in HIBP’s existing breached database.

The login description states that the leaked data also includes tens of thousands of Stripe records, with fields covering name, physical address, purchase amount, and the card type, expiration date, and the last four digits of the card number. Suno clarified that the company itself cannot read full card numbers via Stripe, so the risk of direct card fraud is limited. That may be true, but the combination of name + address + purchase history is exactly the kind of material that makes phishing emails most effective.

Suno spokesperson Rachel Racusen did not deny the number of affected users, and also confirmed that the company experienced a cybersecurity incident in November 2025. However, to date Suno’s official website has not posted any announcement about it, nor has it provided any record of notifying users. What actually pushed the information out was a report by 404 Media—the company is the one that came afterward and admitted it.

Leaked source code exposes the crawler

For record labels, an account leak is just an appetizer. At the same time, the hackers also released Suno’s source code from 2023 to 2024, which directly spells out the sources and scale of the training materials. The list compiled by 404 Media after reviewing the code includes not only YouTube Music, Deezer, and Genius—things the industry had already been guessing—but also audio asset libraries Pond5, Jamendo, Freesound, the International Music Score Library Project (IMSLP), and podcasts fetched via RSS.

Just YouTube Music accounts for 2,013,545 music clips and 113,879 hours. Another group labeled ytm_tagged totals 152,162 hours. Adding Pond5’s 62,117 hours, IMSLP’s 19,514 hours, Genius’s 17,615 hours, Deezer’s 12,287 hours, and Jamendo’s 3,726 hours brings the total to more than 380,000 hours—roughly 43 years of uninterrupted audio. In the code, the folder names are literally written as genius_hq, youtube_music, deezer, and ytm_tagged; even the packaging was lazy at best.

The value of this list is that it doesn’t need to be translated. Over the past two years, for record labels to prove that an AI model has ingested their songs, they have relied on audio fingerprint matching and on reverse inference from the outputs, and they also had to bring expert witnesses to testify in court explaining the algorithms.

Warner is already ashore; Sony and UMG are still in the water

Bring the legal background back to 2024. The Recording Industry Association of America (RIAA), representing Sony Music Entertainment, UMG Recordings, and Warner Records, filed copyright lawsuits against Suno and Udio. The core allegation is that they carried out unauthorized large-scale scraping to train copyright audio recording models. Suno’s defense throughout the case has been fair use; it even admitted in legal filings that it trained on “nearly all music files of reasonable quality” that are obtainable openly on the internet, at a scale of tens of millions of audio recordings.

The three plaintiffs later went their separate ways. Warner Music Group reached a settlement on November 25, 2025, and switched to a licensing partnership; afterward, Suno’s valuation doubled to $5.4 billion. Sony and UMG chose to keep fighting—this month, they have just had their first substantive head-to-head battle over fair use.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned