According to data breach notification site HaveIBeenPwned, the AI generation brand suffered a cyber attack in November 2025, resulting in the data of 55.3 million people being stolen.
The threat actor is reportedly ellie.191, which breached the company after they hacked a staffer using the Shai-Hulud worm supply chain attack, allowing them to access GitHub and cloud service credentials, as well as Suno’s customer list.
According to the page, data includes email addresses, phone numbers, and tens of thousands of Stripe records relating to purchases, including names, purchase amounts, and partial credit card data, including card type, expiry dates, last four digits of cards and physical addresses.
The hack was uncovered only recently by 404 Media, which pointed out that the hack demonstrated how AI companies like Suno train their models.
Already, Suno is involved in several major record industry lawsuits accusing the company of training its models using copyrighted works of artists and musicians.
During the lawsuits, Suno admitted that it had done so, stating that “training data includes essentially all music files of reasonable quality that are accessible on the open internet, abiding by paywalls, password protections, and the like, combined with similarly available text descriptions”, adding that this meant “tens of millions of recordings”.
Suno said the AI was “constructed by showing the program tens of millions of instances of different kinds of recordings gathered from publicly available sources”.
The Recording Industry Association of America (RIAA) accused the company of scraping music directly from YouTube.
“For Suno specifically, this process involved copying decades worth of the world’s most popular sound recordings and then ingesting those copies into Suno’s AI models so they can generate outputs that imitate the qualities of genuine human sound recordings,” the RIAA said.
“And to make matters worse, Suno obtained those copies in the first instance by unlawfully ‘stream ripping’ them from the popular streaming platform YouTube, and circumventing the technological measures designed specifically to prevent such unauthorised copying.”
Now, the source code from the cyber attack has proven the RIAA right.
The data, which was shared with 404 Media, shows source code that looks to be from 2023 and 2024 and outlines the type of data that was scraped.
One file lists data such as “genius_hq, youtube_music, freesound, jamendo, imp, deezer, ytm_tagged,” as well as one note that says “non-music will be filtered out”.
Another note called “youtube_music” suggests that the data was last updated, Suno had scraped “2,013,545 music clips”.
Another file, which outlines the types of datasets Suno had created with the scraped data lists “113,879 hours of youtube_music”, “17,615 hours of genius_hq”, “410 hours of free sound”, “19,514 hours of imslp”, “3,726 hours of jamendo”, “62,117 hours of pond5_music”, “12,287 hours of deezer”, “152,162 hours of ytm_tagged”, and “103 hours of musescore_lyrics”.
Other code seen by the publication shows code that specifically searches for acapella versions of songs on YouTube for AI vocal training.
How Suno scraped the files is unclear, but the data suggests that it used proxies from Bright Data to scrape YouTube. It also reportedly scraped 420,000 podcasts using a tool called PodcastIndex. The podcasts contained at least five 30-minute episodes, and were intended to download around 1 million hours of podcasts.
In a statement, a spokesperson from Suno said: “As we have stated in public filings and disclosures, Suno’s AI models have been trained on publicly available music files and related metadata accessible on third-party websites on the open internet.
“In November of 2025, we determined that Suno had been the subject of a limited security incident that was quickly contained. At the time, we immediately conducted an investigation and verified that the incident primarily involved outdated source code that is no longer in use at Suno and that no sensitive personal information was compromised. Importantly, Suno does not have access to customers’ full credit card numbers in Stripe.
“Based on the limited nature of the customer information believed to be involved, we determined that individual notifications were not warranted under applicable privacy laws.”
The company also sent a training data disclosure, in line with California law.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.