Suno
Incident posture
Linked entities
- Victim
- Suno
- Threat actors
- 1 actor
- Sources
- 11 sources
Timeline
Summary
Suno experienced a security incident that exposed the personal information of approximately 55.3 million users, including email addresses, phone numbers, physical addresses, and Stripe purchase records with partial card details, while also compromising its source code which revealed extensive scraping of music from platforms such as YouTube Music, Deezer, and Genius. The intrusion occurred when a supply-chain worm compromised an employee device, granting the attacker access to credentials that allowed entry to source code repositories and customer databases, and the company did not inform affected users until the breach was reported publicly months later. Although the company characterized the incident as limited and involving outdated code, the exposed data led to a class action lawsuit alleging inadequate security and delayed notification, and added evidence to ongoing copyright litigation with major record labels.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In November 2025 Suno detected a security incident on its network that it described as a limited security incident that was quickly contained. According to Socket.dev’s analysis, the intrusion began when the Shai‑Hulud supply‑chain worm compromised a single Suno employee’s laptop and harvested GitHub and cloud‑service credentials stored on that machine. Using those credentials the attacker gained access to Suno’s source code repositories, its customer database, and the Stripe payment records linked to user accounts. Suno conducted an internal investigation and concluded that the incident primarily involved outdated source code that was no longer in use. The company also stated that it immediately verified that no sensitive personal information was compromised.
The stolen data included approximately 55.3 million unique email addresses, together with names, physical addresses, phone numbers for users who had provided them, and purchase records from Stripe that contained card type, expiration date and the last four digits of the card number; Suno said it does not store full credit‑card numbers or bank‑account details. The attacker also exfiltrated Suno’s source code, which revealed that the company had scraped music and lyrics from platforms such as YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound and the International Music Score Library Project, and had routed traffic through proxy infrastructure from Bright Data. The breach was first reported by the independent outlet 404 Media on July 15 2026, with the hacker using the name ellie.191, who said they had no particular reason for targeting Suno. Have I Been Pwned added the breach to its database on July 20 2026 and reported that 55.3 million accounts were exposed, after which multiple news outlets confirmed the scale. Shai‑Hulud had been active since September 2025, with a second wave in late November 2025 that added a destructive fallback if data could not be exfiltrated.
On July 24 2026 a proposed class action lawsuit was filed in the US District Court for the District of Massachusetts, alleging that Suno knew about the breach in November 2025 but failed to notify affected users and seeking damages and at least ten years of credit‑monitoring services. Suno maintained that it had determined the incident was limited, that no sensitive personal information was compromised, and that individual breach notifications were not warranted under applicable privacy laws; the company also said it had hired a third‑party cybersecurity expert to audit its findings. The breach added to existing legal pressures, as Suno was already defending copyright infringement claims from Universal Music Group, Sony Music Entertainment and Warner Music Group, and had raised over $400 million in a Series D round in June 2026 that valued the company at $5.4 billion. Suno’s CEO had previously said that more than 100 million people had used the service. As of the writing no regulator had announced a public enforcement action against Suno, although plaintiffs’ firm Hall & Attorneys had opened an investigation page seeking affected users. The incident contributed to Suno’s broader legal and regulatory challenges stemming from both the data breach and ongoing copyright litigation.
Sources
Sources available to members: 11 sources.