M3NewsM3 StudiosHouston, TX
Back to M3News

Suno Data Breach: 55 Million Accounts Exposed, and Users Were Never Told

M3 StudiosSpring, TX5 min readJuly 22, 2026

A November 2025 data breach at AI music service Suno exposed 55,282,226 accounts, and the public only learned about it on Monday, July 20, 2026, when the stolen data was added to the Have I Been Pwned notification service. Email addresses, names, phone numbers, physical addresses, purchase records, and partial credit card data are in the set. Suno never notified its users. If you or anyone on your team ever signed up, even once, even to try it, your next fifteen minutes are spoken for, and this piece walks through exactly what to do.

Millions of artists, producers, and creators touched Suno over the past two years, some to experiment, some to sketch ideas, some just to see what the machine would do. Houston creators are in that number. The bill for the free toy arrived this week in two parts: a mountain of personal data circulating among people who steal such things, and a leaked codebase that showed where the platform's training music came from. Both parts carry lessons that outlast this one company.

What leaked, exactly

The verified record at Have I Been Pwned, the breach notification service run by security researcher Troy Hunt, lists the numbers plainly. The breach occurred on November 25, 2025. It surfaced publicly on July 20, 2026, when 55,282,226 unique email addresses entered the database. Where a phone number was used to sign up, the phone number is in the set. Names, physical addresses, and purchase records ride alongside.

The sharpest slice is financial. Tens of thousands of Stripe payment records were caught in the haul, containing customer names, physical addresses, purchase amounts, and partial card details: the card type, the expiration date, and the last four digits. Suno has said it does not hold customers' full card numbers in Stripe, and no full numbers appear in the corpus. Partial card data still matters, because the combination of a real name, a real address, a real purchase history, and the last four digits of a real card is exactly the kit a scam caller uses to sound like your bank.

Eight months of silence

The breach happened in November. The users found out in July, from a third-party notification service, because the company chose quiet. Suno characterized the event as a limited security incident involving outdated source code no longer in use, and reportedly filed a training-data disclosure required under California law while leaving its 55 million account holders unnotified.

Sit with what that gap means in practice. For eight months, every affected user ran the same passwords, kept the same recovery flows, and read incoming emails with the same level of trust, while their contact details, purchase histories, and card fragments circulated without their knowledge. Breach disclosure exists because the window between the theft and the victim finding out is when the damage happens. A company that closes that window protects its users. A company that lets it run for eight months made a different choice, and every creator deciding where to put their work and their payment details should file that choice away.

Texas puts numbers on how disclosure is supposed to work. Under the state's Identity Theft Enforcement and Protection Act, a business holding computerized sensitive personal information on Texans must notify affected residents without unreasonable delay, and no later than the 60th day after determining a breach occurred, and a breach touching 250 or more Texas residents must be reported to the Texas Attorney General, who publishes reported breaches on a public list. Where this incident ultimately lands under that framework, and under the parallel laws of other states, is a question for regulators, and it will turn on how the leaked data gets classified. The two facts a Houston creator can hold today are simpler: the law's clock runs in days, and this one ran in months, from a November theft to a July surprise.

What the leaked code showed

The same breach exposed Suno source code, and reporting on that code is where this story connects to the money fights we cover every week. According to 404 Media, which first reported on the hacked material, the code revealed scraping pipelines pulling training music from streaming and lyrics services including YouTube Music, Deezer, and Genius, from stock and open music libraries including Pond5, Jamendo, and Freesound, and from podcasts through their public feeds. TechNadu's review of the material adds that the attacker reportedly entered through a compromised employee's developer credentials, reaching private code repositories and internal databases.

That is the training-data question answered in source code, the same week Sony answered it with audio fingerprints: on Monday, Sony filed a second federal lawsuit against rival Udio, asserting 30,117 recordings it matched inside Udio's training data through audio fingerprinting, the latest turn in the litigation-and-licensing fight we mapped when the AI licensing deals landed. The fog around what trained these models is gone on every front at once. For working musicians, the leaked pipelines are a reminder with teeth: the catalogs feeding the machines belong to working people, which is why provenance labeling and platform payment policies, like the demonetization of fully AI tracks, moved from debate to policy this year.

If you ever made a Suno account, do this today

The response costs fifteen minutes and nothing else. Run it for every member of your team, and run it tonight, because the people holding this data have had a head start since November.

Check your exposure. Enter your email address at haveibeenpwned.com. It is free, run by a respected security researcher, and it will show every breach your address appears in, this one included.

Rotate the password, everywhere it lives. Change the Suno password, then change it on every other account where you reused it, because credential-stuffing attacks exist precisely for people who reuse. This is the week to let a password manager end that habit for good.

Treat billing emails as hostile until proven real. The most dangerous use of this data is not the card fragment, it is the phishing email that quotes your real name, your real address, and your real purchase to win your trust. Any message about a Suno refund, a subscription problem, or a payment update gets deleted, and anything worth checking gets checked by typing the site address yourself.

Watch the card, calmly. Full numbers were held by Stripe and stayed out of the corpus, so the realistic risk is impersonation, and the fix is the same statement-reading discipline any business owner already runs.

Close what you no longer use. A dormant account is stored risk with zero upside. If the experiment ended a year ago, delete the account, and make that a habit across every service you tried once.

The real price of the free platform

Every free AI creation platform runs the same quiet exchange: the product is free because you are the deposit. Your uploads, your prompts, your listening behavior, your contact details, and your payment fragments sit in somebody else's database, governed by terms you clicked past, protected exactly as well as their weakest employee credential. This breach put a number on that exchange: 55 million.

Turn this week into a standing test, three questions asked before any platform gets your work or your wallet. One: who owns what I make here, under the terms as written today. Two: what will this company hold on me, and can I use it without a stored card, a home address, or my main email. Three: how did it behave the last time something broke, because a company's disclosure history is the only honest preview of how it will treat you when your data is the thing on fire. Free tools can earn a place in a working creator's process, and they earn it the same way every vendor does, by answering questions. This one just answered the third.

The working answer is the one this publication keeps arriving at from every direction. Build on ground you own. Keep your masters and your originals under your control, know what an AI platform's terms actually say about owning what you make there, run your audience through a website and a list you control, and treat every third-party platform, AI or otherwise, as a vendor you can walk away from. Vendors get the minimum: a unique password, a dedicated email alias if you run one, no stored card where you can avoid it, and deletion the day the experiment ends. The wider money map for careers built on owned ground lives in our creator income playbook. Your music deserves that discipline, and after this week, so does your identity.

Frequently asked questions

What happened in the Suno data breach?

AI music service Suno was breached on November 25, 2025. The stolen data covering 55,282,226 accounts became public on July 20, 2026, when it was added to Have I Been Pwned. Exposed data includes email addresses, names, phone numbers, physical addresses, purchase records, and partial credit card data from tens of thousands of Stripe payment records.

How do I check if my data was exposed?

Enter your email address at haveibeenpwned.com, the free breach notification service that verified and indexed this breach. It shows every known breach containing your address and can alert you to future ones.

Were full credit card numbers leaked?

No. The Stripe records contained card type, expiration date, and last four digits alongside names, addresses, and purchase amounts. Suno has said it does not hold full card numbers. The practical risk is convincing phishing and impersonation built from the real details, so treat unexpected billing messages as hostile.

Did Suno notify its users?

Affected users were not notified during the eight months between the November 2025 breach and its July 2026 appearance on Have I Been Pwned. The company characterized the event as a limited security incident involving outdated source code.

Should artists keep their music on AI platforms?

Read the ownership terms before uploading anything you value, keep your masters and originals under your own control, and treat any platform as a vendor: unique password, minimal stored payment data, and account deletion when you stop using it. The platform's security record and its disclosure behavior are now part of that evaluation.

Follow M3 Studios for the craft and money mechanics Houston artists actually use: Instagram @metamusicmedia.x, TikTok @metamusicmedia, YouTube @metamusicmedia. Questions: info@metamusicmedia.com. Building a career on ground you own, from your masters to your audience, is the plan laid out step by step in the Independent Artist Roadmap.

  1. Have I Been Pwned, breach record: Suno (breach date November 25, 2025; added July 20, 2026; 55,282,226 accounts). https://haveibeenpwned.com/Breach/Suno
  2. 404 Media, "Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius." https://www.404media.co/hack-reveals-suno-ai-music-generator-scraped-youtube-deezer-and-genius/
  3. TechNadu, "Suno Data Breach: 55 Million Emails and Stripe Records Exposed." https://www.technadu.com/suno-data-breach-55-million-emails-and-stripe-records-exposed/631566/
  4. Yahoo Tech, "Suno's Data Breach Hit 55 Million Users, and the Company Said Nothing Sensitive Was Exposed." https://tech.yahoo.com/cybersecurity/articles/suno-data-breach-hit-55-182527083.html
  5. Music Business Worldwide, "Sony Music sues Udio again, asserting over 30,000 recordings a judge barred the major from adding to its original case" (July 20, 2026). https://www.musicbusinessworldwide.com/sony-music-files-new-lawsuit-against-ai-platform-udio-asserting-over-30000-sound-recordings-a-judge-barred-it-from-adding-to-its-original-case/
  6. Texas Business and Commerce Code, Section 521.053, Notification Required Following Breach of Security of Computerized Data. https://texas.public.law/statutes/tex._bus._and_com._code_section_521.053
Continue readingMore from M3News
AI artwork
Jul 21, 2026

Who Owns Your Album Cover Art in 2026? The Designer Default, the Written Transfer, and the AI Trap

do you need a record label
Jul 21, 2026

Do You Need a Record Label in 2026? What a Deal Actually Buys, and Who Should Sign One

fake streams
Jul 21, 2026

Is Buying Streams Illegal in 2026? The First Federal Streaming Fraud Sentencing Is Days Away

© Meta Music Media Inc · M3 StudiosM3 Studios logo mark, Houston recording, mixing and visual production studio, Meta Music Media Inc↑ Back to top
M3News · Houston, TX