A cyberattack on the AI music platform Suno has compromised the personal information of over 55.3 million users, according to data breach notification service Have I Been Pwned. The breach, which occurred in November 2025, exposed names, physical addresses, email addresses, phone numbers, purchase records, and partial payment card numbers, including expiry dates, from the company's Stripe account. The stolen dataset also included Suno's source code, revealing how the company allegedly scraped millions of songs from streaming services like Deezer, Genius, and YouTube to train its AI models. Main Developments Have I Been Pwned obtained a copy of the breached dataset, offering the first glimpse into the scale of the data theft. The breach was initially reported by independent news outlet 404 Media, prompting Suno to confirm the incident to TechCrunch after publication. Suno spokesperson Rachel Racusen did not dispute the number of affected users and confirmed the company experienced a security incident in November 2025. Despite the confirmation, Suno has not publicly disclosed the cyberattack on its website or notified individuals that their information was taken. Suno co-founder Mikey Shulman did not respond to TechCrunch's request for comment, and the company did not provide any communication sent to users regarding the breach. Read also: UK Abandons £1.8B Digital ID Plan After Record Petition Background Suno, an AI music generator, has been under legal scrutiny for its data collection practices. Several major record labels are currently suing the company, alleging that its mass scraping of songs and lyrics from streaming platforms violates copyright law. The leaked source code from the breach provides further evidence of these scraping activities, which the company has not publicly denied. The breach itself occurred in November 2025, but only came to light months later through independent journalism. The delay in disclosure raises questions about Suno's transparency and compliance with data breach notification laws, which typically require timely reporting to affected individuals and regulators. Why It Matters This breach exposes sensitive financial and personal data for over 55 million users, putting them at risk of identity theft and fraud. The inclusion of payment card details from Suno's Stripe account is particularly concerning, as partial card numbers and expiry dates can be used in targeted phishing attacks or combined with other stolen data. Additionally, the theft of source code not only threatens Suno's intellectual property but also reveals the company's alleged copyright violations, potentially strengthening the record labels' lawsuits. The incident underscores the broader risks of AI companies collecting vast amounts of data without robust security measures, especially when facing legal challenges over their data practices. What's Next Suno has not indicated when it will publicly acknowledge the breach or notify affected users. Under data protection regulations in various jurisdictions, the company may face fines or legal action for failing to disclose the incident promptly. The record labels' lawsuits against Suno are ongoing, and the leaked source code could become key evidence in those cases. Users affected by the breach should monitor their financial accounts for suspicious activity and consider placing fraud alerts on their credit files. Have I Been Pwned will allow individuals to check if their data was compromised using the breached dataset.