Suno, an AI music generator that has drawn considerable attention, suffered a massive security breach—one it appears not to have disclosed publicly.

According to TechCrunch reporting, the cyberattack at Suno compromised the personal information of more than 55.3 million users. The breach, which occurred in November 2025, exposed names, physical addresses, email addresses, phone numbers, purchase histories, and partial payment card details obtained from Suno's Stripe account. The company has not yet publicly disclosed the incident to affected users or announced it on its official channels.

The discovery was made by data breach notification service Have I Been Pwned, which obtained a copy of the stolen dataset. Suno co-founder Mikey Shulman did not respond to requests for comment. A company spokesperson later confirmed the November 2025 security incident without disputing the scale of the breach.

The stolen data included Suno's source code, which revealed how the platform has been scraping millions of songs and lyrics from major streaming services—including Deezer, Genius, and YouTube—to train its AI models without permission.

For Bollywood producers and independent artists considering AI tools, the implications are substantial. Multiple major record labels are already suing Suno over copyright violations. The leaked source code provides detailed evidence of how extensively the platform has been collecting copyrighted material.

Suno has not notified millions of affected users, issued a press release, or offered a security update. When a platform refuses to acknowledge a breach of customer data, it raises questions about its approach to accountability—particularly for a service built on training models using artists' work.

The breach is likely to accelerate the legal battles already underway against the company.