Have I Been Pwned confirmed on July 20, 2026, that a Suno data breach exposed 55.3 million user accounts, according to Troy Hunt’s breach notification service. The AI music platform has not disclosed the incident publicly or notified affected users, per TechCrunch.
Quick Summary – TLDR:
- Troy Hunt’s Have I Been Pwned service confirmed 55.3 million Suno accounts were exposed in a breach dating to November 2025.
- The stolen data includes email addresses, phone numbers, names, physical addresses, and purchase records, per HIBP.
- Tens of thousands of Stripe payment entries carried partial credit card data, including card type, expiry date, and the last four digits.
- Suno has not disclosed the breach publicly or notified affected individuals as of this report.
- Warner Records settled its RIAA-backed copyright suit against Suno and now has a commercial partnership with the company, while Sony Music and Universal Music Group continue their claims.
What Happened?
Have I Been Pwned confirmed the scale of the Suno data breach for the first time, tying the exposure to 55.3 million user accounts. The data set contains more than 55 million unique email addresses, with phone numbers included where a user had signed up with one instead.
A smaller, more sensitive slice of the dump came from Suno’s payment processor. Tens of thousands of Stripe records included names, physical addresses, purchase amounts, and partial card data. Suno addressed the exposure directly: Suno does not have access to customers’ full credit card numbers in Stripe.
That statement caps the worst case damage at partial fields rather than full card numbers, which limits direct fraud risk. The surrounding personal data (name, address, purchase history) still matters for anyone targeted with a follow-up scam.
New breach: Data from Suno’s November 2025 breach surfaced publicly last week. The corpus contained over 55M unique email addresses plus tens of thousands of Stripe payment records. 24% were already in @haveibeenpwned. More: https://t.co/RRDVGN5zFF
— Have I Been Pwned (@haveibeenpwned) July 20, 2026
The Eight-Month Disclosure Gap
The breach happened in November 2025, but was only recently revealed thanks to reporting by independent news outlet 404 Media. Suno has not yet publicly disclosed the cyberattack or notified individuals that their information was taken. That gap left millions of accounts unaccounted for well after the intrusion occurred.
A months long silence on a data breach touching tens of millions of accounts is exactly the kind of gap that data-protection regulators in the EU and UK, and state attorneys general in the US, are built to scrutinize under their own breach notification timelines. Whether Suno falls under any specific one depends on where its affected users live.
The exposed Stripe fields turn this into more than a routine email leak. A name, address, purchase history, and a card’s expiry date and last four digits are the details a scammer needs to sound legitimate on a followup phishing call or text. Affected users can help reduce that risk by treating any unsolicited message referencing a Suno purchase as suspicious.
Enabling multi-factor authentication on a Suno linked email account helps reduce account takeover risk. Watching card statements for small unfamiliar charges also helps limit exposure, since small test charges are a common pattern fraudsters use before attempting larger transactions.
Source Code Leak Feeds the Copyright Fight
The breach also carried a payload well beyond user records. The individual who claimed responsibility for the breach also supplied source code dating from 2023 and 2024, which they said showed Suno scraping millions of songs and lyrics from services including YouTube Music, Deezer, and Genius to train its AI. Suno has acknowledged training its AI on music available on the open internet, arguing that this constitutes fair use.
That code lands inside an active legal fight. The RIAA sued Suno and rival Udio in 2024 on behalf of Sony Music Entertainment, UMG Recordings, and Warner Records, alleging mass scraping of copyrighted songs without permission. Warner has since settled its litigation with Suno and begun a commercial partnership with the company, while Sony and UMG are continuing their claims in court.
A security incident handing plaintiffs a leaked look at the defendant’s own training pipeline is an unusual way for evidence to surface in a copyright case. It raises the stakes for Suno regardless of how the breach itself gets resolved.
SQ Magazine’s Takeaway
Suno’s breach, touching 55.3 million accounts, reads less like one failure than like two problems layered on each other. The data exposure itself is serious but partially contained, since Stripe’s tokenization kept full card numbers out of reach. The bigger issue is process. A long gap between the breach and any public accounting of it left affected users unable to judge their own exposure.
Speed of disclosure, not just the sophistication of the intrusion, determines how much damage reaches end users. Stripe’s design worked as intended here. Suno’s communication did not keep pace with it.
What’s next depends on regulators and the litigants already circling Suno. Watch for whether a data protection authority opens a formal inquiry into the notification delay, since that timeline tends to draw scrutiny once it becomes public. Sony and UMG’s ongoing case against Suno may also seek to use the leaked source code as discovery material, which could speed up that litigation.
Affected users should treat their Suno-linked email as compromised, watch for unusual charges tied to any Suno purchase, and expect an eventual notification email. Checking Have I Been Pwned directly remains the fastest way to confirm exposure right now.