A hacker had Suno user data for 8 months before anyone said a word
55.3 million accounts, names, addresses, phone numbers, and partial payment records, breached in November 2025. Suno stayed quiet until Have I Been Pwned and 404 Media surfaced it in July.
A hacker had 55M Suno users' data for 8 months. The company said nothing until it leaked.
A hacker stole personal data on 55.3 million Suno users in November 2025. Suno did not tell anyone. The breach only became public in July 2026, after 404 Media and Have I Been Pwned surfaced it independently.
What was actually taken
Names, physical addresses, emails, phone numbers, purchase history, and tens of thousands of partial Stripe payment records, card type, expiry, and last four digits, not full card numbers. Troy Hunt, who runs Have I Been Pwned, said plainly that "malicious actors can use this information to set up more credible phishing campaigns against Suno users."
The part that matters for Suno's other fight
The same leaked source code that exposed the breach also revealed details of Suno's training pipeline, specifically that it scraped Deezer, Genius, and YouTube and YouTube Music content. Suno is already facing copyright litigation over its training data, and this leak hands plaintiffs a more concrete account of what actually went into the model than anything from discovery so far.
Why a build studio cares
An eight month gap between a breach and disclosure is the actual story here, not the raw user count. Any product handling user data, AI-native or not, has to treat breach detection and disclosure timeline as a real operational requirement, not a compliance checkbox. A company staying silent for eight months is the difference between a bad week and a trust problem that outlives the breach itself.
Next step: check Have I Been Pwned if you use Suno, and read TechCrunch's coverage. If your product's breach response plan has never actually been tested, write to us at hello@gattyworks.com.