Over 55 Million Suno Users Affected in Data Breach as Leaked Source Code Reveals AI Training Practices
साउन ७, २०८३ १६:१३
Kathmandu. More than 55.3 million users of AI music generation platform Suno were affected in a major data breach disclosed months after the incident, with leaked source code also raising fresh allegations that the company used unauthorized data from online music platforms to train its artificial intelligence models.
The breach, which reportedly occurred in November 2025, was confirmed by data breach notification service Have I Been Pwned (HIBP). The website revealed for the first time that hackers obtained personal information belonging to more than 55.3 million users.
According to HIBP, the compromised data includes users' names, email addresses, physical addresses, phone numbers, purchase records, and payment-related information. Thousands of records linked to Suno's payment processor, Stripe, were also exposed, including card types, expiration dates, and the last four digits of payment cards. Suno, however, said it does not store customers' full credit card numbers and that complete card details remain secure.
The incident has also drawn attention because hackers reportedly obtained Suno's internal source code. A hacker using the alias "ellie.191" claimed the leaked code reveals how the company collected large volumes of music and audio data from online platforms to train its AI models.
According to the leaked documents, Suno allegedly scraped more than two million audio clips from YouTube Music, over 17,000 hours of lyrics and related data from Genius, and more than 12,000 hours of music from Deezer. The documents also suggest data was collected from platforms including Pond5, Jamendo, Freesound, and IMSLP, while references to third-party services such as Bright Data indicate efforts to extract vocal-only audio from YouTube.
The revelations come as Suno faces ongoing copyright lawsuits filed by the Recording Industry Association of America (RIAA), Sony Music Entertainment, and UMG Recordings. The music industry alleges the company trained its AI models on copyrighted works without authorization, while critics have accused Suno of generating so-called "AI slop" using artists' creative works.
Suno maintains that using music publicly available on the internet falls under the principle of fair use. However, the RIAA argues that the company unlawfully obtained music through stream-ripping methods that bypassed YouTube's technical protections. The newly leaked source code is expected to strengthen those allegations.
Responding to the incident, Suno spokesperson Rachel Racusen acknowledged that the company experienced a "limited security incident" in November 2025 but said it involved only outdated source code rather than systems currently in production. The company also said it did not notify individual users because it concluded that applicable privacy laws did not require such disclosure.
Cybersecurity experts have criticized Suno for remaining silent about the breach despite its scale. Users are being advised to change their passwords immediately and enable two-factor authentication (2FA) to protect their accounts better.
The incident could also affect users in Nepal, where AI-generated music has become increasingly popular. If Nepali users were among those using Suno, their personal and purchase information may also have been exposed. The leaked source code has also fueled concerns that Nepali songs and vocal recordings available on YouTube may have been used to train AI models without the permission of rights holders.
पछिल्लो अध्यावधिक: साउन ७, २०८३ १६:१३
