Suno lost the data of 55 million people and did not tell them
Have I Been Pwned lists 55.3 million addresses from a November 2025 Suno breach. Check whether yours is there, and what to do next.
If you have ever made a track on Suno, your email address is probably in a file stolen from the company in November 2025. You did not learn that from Suno. You learned it from a breach notification service, eight months later. Here is what the stolen file contains, and what to do if your address is in it.
Inside the Have I Been Pwned listing
Have I Been Pwned's Suno entry puts the breach in November 2025, records the date added as 20 July 2026, and gives the number of affected addresses as 55.3 million. Music Business Worldwide reports the precise count as 55,282,226 addresses, a quarter of them already seen in earlier breaches.
The data classes on that entry are listed plainly: email addresses, names, partial credit card data, phone numbers, physical addresses, purchases. Passwords are not among them.
The entry also narrows down who got the worst of it. Phone numbers appear "where they had been used as the sign-up method". A smaller slice, "tens of thousands of Stripe records relating to purchases", carried "names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits". The same page records what the company told the service: "Suno does not have access to customers' full credit card numbers in Stripe".
The eight months in the middle
404 Media broke the story on 15 July 2026. TechCrunch published on 21 July, writing that Suno "has not yet publicly disclosed the cyberattack, or notified individuals that their information was taken".
Suno's account of its November 2025 decision went to 404 Media, as summarised by Music Business Worldwide. A spokesperson said the company had been "the subject of a limited security incident that was quickly contained", that its investigation "verified that the incident primarily involved outdated source code that is no longer in use at Suno", that "no sensitive personal information was compromised", and that on that basis individual breach notifications "were not warranted under applicable privacy laws".
After the TechCrunch report, spokesperson Rachel Racusen did not dispute the number affected and confirmed a security incident in November 2025. A proposed class action followed on 24 July in the US District Court for the District of Massachusetts, and Suno told Music Business Worldwide it does not store full payment card information and had hired a third-party cybersecurity expert to audit its initial findings.
We checked Suno's blog again on 12 September 2026. The most recent post is the v6 announcement of 9 September 2026, and there is nothing there about the incident. The disclosure came from a hacker, a reporter and a breach database, in that order.
A statement to a journalist is not a notification to you. If no email reached you about this, you are not an exception, and you should assume none is coming.
The allegation buried in the same theft
All of this surfaced only because the person who took the data also took source code. 404 Media, which reviewed the material, reported that code apparently dating from 2023 and 2024 carried scraping instructions naming YouTube Music, Deezer, Genius and stock libraries including Pond5 and Jamendo, with one file logging 2,013,545 music clips. The hacker, who uses the name ellie.191, told the outlet they got in by infecting a Suno employee with Shai-Hulud, a supply-chain worm that steals credentials.
That is an allegation drawn from leaked material as described by the outlet that read it, not a finding by any court. It matters anyway: one breach exposed both the customers and the company's record of where its training material came from.
How to check whether you were in it
Open haveibeenpwned.com and enter the email address you used at Suno. The Suno records are in it.
Repeat the check for every address you might have signed up with, including an old one you no longer read. A free account made years ago still put you in the file.
Read the compromised data classes on the result. That tells you whether you are in the email-and-phone group or, if you ever paid, the Stripe group.
Sign up on Have I Been Pwned's Notify Me page, which emails you when your address turns up in a future breach. For a company that decides not to notify you, that is the nearest thing to a warning.
Only ever type your email address into a breach checker. A site that wants your card number, birthday or national ID number before it will tell you anything is running a different business.
What a partial card number and an expiry date are good for
Not buying things. Suno's statement to Have I Been Pwned says it does not hold full card numbers in Stripe, and a card type, an expiry date and four digits will not complete a payment on their own. What that record does is make a stranger sound like your bank. Somebody who can recite your name, your street, your last Suno payment amount and the last four digits of the card you used can make a phone call you believe.
Tell your bank or card issuer that partial details of your card were in a breach and let them decide whether to reissue it. That is the limit of our money advice.
Treat any call, text or email quoting those details as unverified, however convincing. Hang up and dial the number printed on your card.
Change your Suno password, then change it everywhere you reused it. Have I Been Pwned's recommended actions on this breach are two: change the password on every account where it was used, and enable two-factor authentication wherever it is supported.
Start that second step with the email account tied to your Suno login. That address is now publicly known to be real and active.
What disclosure you are owed, in Europe
The GDPR rules are short enough to read yourself. Under Article 33, a controller must report a personal data breach to its supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it", unless the breach is unlikely to result in a risk to people's rights and freedoms. A late report has to carry reasons for the delay.
Article 34 covers you directly. Where a breach "is likely to result in a high risk to the rights and freedoms of natural persons", the controller must communicate it to the affected person without undue delay, in clear and plain language. The carve-outs include encryption of the affected data, later measures that remove the high risk, and disproportionate effort, which requires a public communication instead. Article 77 gives you the right to complain to a supervisory authority where you live.
Whether those articles reach any given Suno user is for regulators and courts to decide, and we are a Belgian company writing an explainer, not your lawyers. What the text shows is that "notifications were not warranted" is a claim about the law, now being tested in litigation.
The question to ask before your next sign-up
Every AI service you use holds a version of this file. The question worth asking is what a company says it keeps and for how long. Ours is in the retention section of our privacy policy, in periods rather than adjectives: deleted conversations hidden immediately and removed within 30 days, request logs 30 days, analytics 12 months, error and crash reports 90 days. Delete your account and your conversations, files, images, memories and login details go within 30 days, with a restricted archive kept for a year to prove the erasure happened and payment records for seven years, as Belgian law requires.
On training: we do not train on your conversations. What the provider behind a given model does with them varies by model, and the models where we know of a difference carry a notice on their info card in the picker.
Those precautions cannot undo the breach. It does mean you can look it up yourself this afternoon, instead of waiting to read it in a stranger's file.