55M Impacted by Suno Data Breach

Suno, an AI music generation tool, was breached in November 2025. This month, it was revealed that 55.3 million emails were reportedly impacted by this breach, alongside other personal information such as:
- Names
- Phone numbers
- Purchases and partial credit card data
- Physical addresses
Suno is facing lawsuits accusing the company of training its AI on copyrighted materials. Following the hacking, 404 Media reports the stolen data revealed Suno “scraped millions of songs and lyrics from YouTube Music, Deezer, and Genius, as well as from the stock music libraries Pond5, Jamendo, Freesound, the International Music Score Library Project, and podcasts via RSS feeds,” which may also bring questions about IP protection into the matter as well.
Seemant Sehgal, Founder & CEO of BreachLock, comments, “When the disclosed scope of a breach grows this significantly in such a short period, it suggests that either the initial investigation was rushed or the organization lacked adequate visibility into its environment.
“The scale and variety of the exposed data raise serious questions about internal segmentation, security monitoring and incident readiness. Regulators and customers will spend less time focused on the 55.3 million figure than on what Suno knew, when it knew it and how it responded. Organizations that cannot establish what was accessed, when and from where within the first 72 hours will find their disclosure decisions harder to defend than the breach itself.”
Steven Swift, Managing Director at Suzu Labs, adds, “Customers have considerable breach fatigue after being notified repeatedly that their names, addresses, email addresses and other personal information have been exposed. At this point, individuals should assume that much of their personal information has already been compromised.
“The AI component is not necessarily the central issue here. There has been no public evidence directly attributing Suno’s security posture to its use of AI-generated code. However, rapidly growing AI companies may rely heavily on AI-assisted development, which can introduce security weaknesses when code is deployed without proper review and testing.
“Most breaches result from organizations failing to follow established security practices. Companies using AI in their applications, automation and infrastructure need a comprehensive security baseline and regular testing to confirm that their controls work. That should include at least annual penetration testing of hosted applications, services, internal networks and devices.
“Testing alone is not enough. Organizations also need to remediate the vulnerabilities that testing identifies. Too many companies conduct annual penetration tests only to receive the same findings year after year.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







