Suno AI suffered a significant data breach in November 2025, exposing over 55 million accounts, with details emerging only after eight months of silence. The breach was disclosed following an investigative report by 404 Media on July 14, 2026, based on information from a hacker known as “ellie.191.” This hacker accessed Suno’s systems via a supply-chain compromise of employee credentials, utilizing the Shai-Hulud worm, a self-replicating malware that targeted the npm ecosystem since September 2025.
According to Have I Been Pwned, the breach compromised more than 55.3 million unique email addresses, user phone numbers, and tens of thousands of Stripe purchase records. These records included names, physical addresses, purchase amounts, and partial credit card information, such as card type, expiry date, and the last four digits. Suno stated it does not have access to customers’ full credit card numbers.
Despite the scale of the breach, Suno did not notify affected users, describing the incident as a “limited security incident” involving “outdated source code” and asserting that no “sensitive personal information” was compromised. The company’s claim that notifications were not required under applicable privacy laws has been criticized, as U.S. breach-notification statutes typically mandate disclosure when personal data is exposed.
Troy Hunt, operator of Have I Been Pwned, confirmed on July 19 that data from the November 2025 breach had become public the previous week. The breach not only affected customer data but also exposed internal source code that disclosed Suno’s training data practices, which included scraping over two million music clips from YouTube Music, and content from Deezer, Genius, and stock music libraries.
This disclosure has intensified ongoing copyright infringement litigation against Suno by major record labels, including Universal Music Group and Sony Music. The Shai-Hulud worm that facilitated the breach had already prompted a high-severity alert from India’s Computer Emergency Response Team, warning of risks to startups, fintech platforms, and e-governance applications that rely on npm-based software.




