CSIDB logo
Incident

Paidwork

Incident posture

Attack window
Mar 2026
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-08-21 00:52

Linked entities

Victim
Paidwork
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

Suno suffered a breach in which attackers obtained source code and user data, leading to the exposure of 55.3 million unique email addresses, phone numbers, and tens of thousands of Stripe payment records containing names, physical addresses, purchase amounts, and partial card details such as card type, expiration date and last four digits. Paidwork was also targeted, with a leaked 11 GB database reportedly containing information of about 22 million users; Have I Been Pwned found 23.3 million unique email addresses alongside names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, financial transactions and user profile information, while the company stated it has no confirmed evidence of compromise and is investigating the claim.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In November 2025, hackers gained unauthorized access to the systems of Suno, an AI music generator, and exfiltrated source code and user data. The intrusion remained undisclosed until early July 2026, when the technology news outlet 404 Media reported that the attackers had obtained Suno’s source code, which revealed that the company had been scraping music and podcasts from platforms such as Deezer, YouTube, and Genius. Shortly after the 404 Media report, the breach notification service Have I Been Pwned (HIBP) analyzed the leaked data and identified 55.3 million unique email addresses tied to Suno accounts. In addition to email addresses, the exposed information included phone numbers and tens of thousands of Stripe payment records containing names, physical addresses, purchase amounts, and partial payment card details such as card type, expiration date, and the last four digits of the card number.

Separately, threat actors claimed to have compromised Paidwork, a gig‑work platform where users perform small tasks for payment, in March 2026. Around the week of July 15 2026, an 11 gigabyte database allegedly stolen from Paidwork was posted online, with the leaker asserting that it contained information for roughly 22 million users. HIBP’s examination of the leaked material revealed 23.3 million distinct email addresses, together with names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, financial transaction logs, and various user profile fields. The data set thus encompassed a broad range of personal and financial identifiers associated with Paidwork’s user base.

SecurityWeek contacted both Suno and Paidwork for comment on the disclosures. Paidwork responded with a statement acknowledging awareness of the Have I Been Pwned report but emphasizing that, at the time of the statement, the company had no confirmed evidence that its systems or user accounts had been compromised in the incident referenced by HIBP. Paidwork added that it treats such reports seriously and has already escalated the matter to its internal security team for further investigation. No public statement from Suno regarding the breach or any remedial actions was included in the reported coverage.

Sources

Sources available to members: 1 source.

CSIDB