Suno breach exposed millions of users' names, phone numbers and addresses
A Suno breach exposed more than 55 million email addresses, plus names, phone numbers and home addresses, months before many users learned it happened.

A Suno breach exposed names, phone numbers and physical addresses for millions of users, and the incident sat hidden for roughly eight months before it came to light. Have I Been Pwned said the November 2025 intrusion touched more than 55 million unique email addresses, making it one of the larger AI-platform exposures to surface publicly.
The compromised data was not limited to email addresses. Phone numbers were included when users had used them as the sign-up method, tying accounts to a direct contact line. The breach also included tens of thousands of Stripe records tied to purchases, and those records held names, email addresses, physical addresses and partial payment details. For people who use the service for creative work, those combinations can turn a music account into a roadmap for phishing, account takeover and unwanted contact at home.

Suno said the company was breached in November and that “no sensitive personal information was compromised,” a statement that now sits uneasily beside the exposed names, addresses and payment-related records tied to purchases. The delayed disclosure matters because the breach was not public when it happened, leaving users in the dark while their personal data remained in circulation for months.
Anyone who used Suno should assume the leaked information can be used to build highly tailored scams. If a phone number was used to sign up, that number is part of the exposure; if a purchase went through Stripe, the exposed records may connect a name and address to payment activity. Passwords should be changed anywhere the same login was reused, and bank or card statements tied to Suno purchases should be checked for unfamiliar activity.
The disclosure lands while Suno is already under intense legal scrutiny. Reuters said the company and rival Udio were fighting major record-label lawsuits in August 2024, and later reporting tied the breach to code suggesting Suno scraped YouTube, Deezer and Genius for training data. That combination of litigation, data questions and delayed notification leaves Suno facing a trust crisis that reaches well beyond one hacked database.
This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.
Did this article answer your question?


