Mastodon Mastodon Mastodon Mastodon

Have I Been Pwned Confirms Massive Suno Breach with Stripe Data

Photo of author

CyberSecureFox Editorial Team

Published:

The Have I Been Pwned service has added to its database data stolen in the breach of Suno, a popular AI music generator. According to HIBP, the dump contains 55.3 million unique email addresses, phone numbers and tens of thousands of records from the Stripe payment system, including partial bank card details. All Suno users are advised to check their addresses via HIBP and take steps to protect linked accounts and payment instruments.

Scope and contents of the leak

According to the entry on the Have I Been Pwned website, the compromised Suno dump includes several categories of personal data:

  • 55.3 million unique email addresses — the main body of the leak;
  • Phone numbers — reportedly only those users are affected who used a phone number instead of an email address when registering;
  • Stripe records — tens of thousands of records presumably containing customer names, home addresses, purchase amounts and partial bank card details (card type, expiration date, last four digits of the number).

It should be emphasized that the detailed set of fields in the Stripe records and the exact conditions under which phone numbers were included are based on reports in open sources and have not been independently verified or confirmed by an official statement from Suno. Nevertheless, the very fact that the leak appears in the HIBP database indicates that the data has been reviewed by Troy Hunt, the operator of the service, who is known for a strict approach to dump validation.

Conflict with the company’s position

Particular attention should be paid to the discrepancy between HIBP’s analysis and Suno’s initial response to the incident. According to available information, after the breach company representatives stated that the leak did not affect users’ personal data. The presence in the dump of tens of millions of email addresses and Stripe payment records directly contradicts this claim.

It should be noted that the original Suno statement is not included in a verified set of sources, so the exact wording and context of the company’s position remain unconfirmed. However, if the contradiction does in fact exist, it raises serious questions about the transparency of Suno’s response to the incident and its compliance with obligations to notify affected users.

Timeline and context of the incident

According to available data, the Suno breach occurred in November 2025, but public information about it emerged significantly later. The stolen materials were reportedly provided to journalists at 404 Media and included not only user data but also the platform’s source code.

Analysis of the stolen data also revealed that Suno developers had allegedly been massively downloading content from YouTube Music, Deezer, Genius and other platforms to train their models. It is mentioned that one of the files contained links to more than 2 million clips from YouTube Music, and the total duration of the collected audio was measured in hundreds of thousands of hours. These data have not been verified by independent sources, but they echo Suno’s previously known position: the company acknowledged using music from “open sources on the internet” and insisted on the applicability of the fair use doctrine.

This aspect of the incident goes beyond cybersecurity and touches on the heated debate over copyright in training generative AI models. The leak of Suno’s source code and internal data may become a significant argument in rights holders’ lawsuits against the company.

Impact assessment

The scale of the leak — 55.3 million unique email addresses — places the Suno incident among the largest breaches of 2025. The main risks for affected users are:

  • Phishing and social engineering — compromised email addresses can be used for targeted phishing campaigns, especially when combined with names and addresses from Stripe records;
  • Credential stuffing — users who reuse the same password across multiple services risk losing access to other accounts;
  • Financial fraud — partial bank card data is not sufficient on its own to carry out transactions, but in combination with other leaks it can be used for identity verification during attacks on banking services.

Recommendations for Suno users

  1. Check your email via Have I Been Pwned — the service will show whether your address is present in the Suno dump;
  2. Change your password on Suno and on all services where the same password was used;
  3. Enable two-factor authentication on all critical services linked to the compromised email address;
  4. Review statements for bank cards used to pay for a Suno subscription for signs of suspicious transactions;
  5. Be prepared for phishing — emails allegedly from Suno or related services asking you to “verify your data” or “update payment information” are highly likely to be fraudulent.

The Suno incident illustrates a typical problem for AI startups: rapid growth of the user base with insufficient attention to infrastructure security and to transparency in communicating with users after incidents. Anyone who has ever registered with Suno should immediately check their email via HIBP and, if necessary, have the bank card used to pay for the service reissued.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.