Overview
- Have I Been Pwned and multiple outlets report that the breach exposed personal data for about 55.3 million users including names, addresses, emails, phone numbers, purchase histories, and partial Stripe card details.
- The intrusion occurred in November 2025, when attackers stole internal source code and ingestion logs that were not publicly revealed until July 2026.
- Leaked code and logs appear to document automated scraping of millions of songs and lyrics from services such as YouTube, Deezer, and Genius for model training, a point now cited by major record labels in ongoing copyright suits.
- Suno says the exposed files were outdated and that full card numbers were not taken, and the company has not issued broad user notifications, a disclosure gap that raises legal and regulatory questions.
- The episode may spur tighter rules on AI training data, stricter breach‑notification enforcement, and increased interest in platforms that can prove licensed, auditable data provenance.