Suno's 55-million-user breach data goes public, months after the original hack
Stolen names, phone numbers, addresses, and Stripe payment records from AI music generator Suno are now circulating openly, per Have I Been Pwned.
What matters
- Suno's November 2025 breach data is now publicly available, per Have I Been Pwned.
- The dataset includes over 55 million unique email addresses, plus names, phone numbers, and physical addresses.
- Tens of thousands of Stripe payment records are also part of the exposed data.
- Roughly 24% of the exposed email addresses were already in HIBP's database from prior incidents.
- The breach is one of the largest AI-related data exposures in recent months.
Security advisory
- Affected:
- Over 55 million unique email addresses, plus customer names, phone numbers, physical addresses, and tens of thousands of Stripe payment records
What happened
Have I Been Pwned (HIBP) has confirmed that a dataset tied to the November 2025 breach of AI music generator Suno is now publicly available. The collection contains more than 55 million unique email addresses, along with customer names, phone numbers, and physical addresses. According to HIBP, tens of thousands of Stripe payment records are also included in the exposed data.
The breach itself is not new — it dates to November 2025 — but the stolen information has only recently begun circulating openly. HIBP announced that the dataset became publicly available during the week preceding its disclosure, meaning the window for misuse has widened considerably. Approximately 24% of the exposed email addresses were already present in HIBP's database from prior incidents, but the remainder represents fresh exposure for users who may not have known they were affected.
Suno, which lets users generate full songs from text prompts using AI, has grown rapidly and amassed a large consumer base. That scale is now reflected in the size of the breach: 55 million records makes this one of the largest AI-related data exposures in recent months.
Why it matters
Data breaches rarely end when attackers first gain access. The real damage often begins months later, when stolen information spreads across cybercriminal communities and eventually becomes publicly searchable. That is precisely the pattern playing out here.
For affected users, the risks are concrete: credential theft, phishing campaigns, identity fraud, and financial scams all become more likely once personal details like names, phone numbers, and physical addresses are in the wild. The inclusion of Stripe payment records — even if they don't contain full card numbers — adds a financial dimension that could enable targeted social-engineering attacks.
For the broader AI industry, the incident underscores a growing tension: consumer AI products are scaling faster than many companies can secure them. Suno is not the first AI startup to face a major breach, and it likely won't be the last. As AI tools collect rich user data — usage patterns, creative prompts, payment information — they become increasingly attractive targets.
The timing also matters. With the breach data now public, anyone who used Suno before November 2025 should assume their information is potentially accessible to bad actors, regardless of whether Suno has notified them directly.
What to watch
- User response: Whether Suno issues a fresh notification to customers now that the data is publicly circulating, and what remediation — if any — the company offers.
- Regulatory scrutiny: Data protection authorities in the EU and U.S. may take renewed interest given the scale and the public availability of the dataset.
- Downstream attacks: Watch for phishing campaigns or identity-fraud spikes that can be traced back to the Suno dataset in the coming weeks.
- Industry precedent: Whether this breach prompts other AI startups to audit their data-handling and breach-response practices.
What to do next
Developers
Check whether your personal email appears in the Suno breach via Have I Been Pwned, and rotate any passwords reused across Suno and other services.
Developers often reuse credentials across platforms; the public availability of this dataset makes credential-stuffing attacks highly likely.
Founders
Review your startup's incident-response plan and data-retention policies to ensure you can notify users promptly if a similar breach occurs.
The Suno breach shows that breach impact escalates when stolen data goes public months later; preparedness reduces both user harm and reputational damage.
PMs
Audit what personal data your AI product collects and whether each field is strictly necessary, especially payment and contact details.
Minimizing stored PII reduces both breach impact and regulatory exposure, as demonstrated by the inclusion of Stripe records in this dataset.
Investors
Factor data-security posture and breach-response readiness into due diligence for consumer AI startups, not just growth metrics.
A 55-million-user breach at a fast-growing AI company illustrates how security incidents can materially affect user trust and regulatory risk.
Operators
Alert customer-support and security teams to watch for phishing or social-engineering attempts referencing Suno account details.
Now that names, phone numbers, and addresses are public, attackers can craft highly targeted scams that reference real user data.
Testing notes
Caveats
- This is a security incident, not a testable product or feature release. Users can check their exposure via Have I Been Pwned (haveibeenpwned.com), but the article itself does not describe a testable artifact.