01Summary
A hacker said they breached Suno using one employee's stolen login and reached outdated source code. Have I Been Pwned added the breach on 20 July 2026: 55.3 million unique email addresses, plus phone numbers, names, addresses and tens of thousands of Stripe purchase records with card type, expiry date and last four digits. Source code revealing details of Suno's AI training practices was also taken. Suno decided that individual notifications were not required.
02Technical analysis
- Attack vector
- Stolen employee credentials
- Initial access
- Valid accounts
03Victims and impact
Countries affected
- Global
04Data exposed
Data types
- Email addresses
- Phone numbers
- Names
- Physical addresses
- Partial card data
- Source code
05Timeline
- 2025-11-01Breach occurs (November 2025).
- 2026-07-20Have I Been Pwned adds 55.3 million accounts.
06Reaction and fallout
Public reaction
Criticism that Suno chose not to notify users.
07Disclosure and media
Publishing organisations
- TechCrunch
- The Register
- Cybernews
08Sources
References
- [1]TechCrunch: https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/
- [2]The Register: https://www.theregister.com/security/2026/07/21/breach-of-ai-music-platform-suno-affected-55m-user-accounts/5275514









