Suno breach exposes 55M accounts as HIBP confirms dataset

Have I Been Pwned breach card for Suno.Have I Been Pwned
Have I Been Pwned breach card for Suno.Have I Been Pwned
Tools & Apps

Have I Been Pwned has added Suno's November 2025 breach, listing more than 55 million unique email addresses plus phone numbers and a smaller set of Stripe purchase records with names, addresses, purchase amounts, and partial card details.

Have I Been Pwned has added Suno's breach to its public database, putting a concrete number on a security incident that had been circulating through reporting and leaked-data analysis: more than 55 million unique email addresses. The record says the breach happened in November 2025 and surfaced publicly in July 2026.

For users, the practical issue is not only account access. HIBP says phone numbers were present where people used them for signup, and a smaller set of Stripe purchase records included names, physical addresses, purchase amounts, card type, expiry date, and the last four digits of payment cards.

Suno users should treat this as identity-risk data

Email addresses alone are enough to fuel credential stuffing and phishing. The Suno dataset appears more sensitive because it can connect an AI music account to a phone number, purchase history, physical address, and partial card metadata for some customers.

HIBP notes that Suno does not have access to full Stripe card numbers, which matters. Partial card details do not let an attacker spend from the card by themselves. They can still make social engineering more convincing when paired with a name, address, purchase amount, and the fact that the person used Suno.

The immediate user playbook is direct: check HIBP for affected email addresses, change reused passwords, turn on two-factor authentication where available, and watch for Suno-themed payment, copyright, refund, or account-verification messages. Users who signed up with a phone number should be alert for SMS phishing and support-impersonation attempts.

HIBP and reporters put numbers on an older incident

The breach date matters because it separates the incident from the disclosure window. HIBP describes the compromise as a November 2025 Suno breach that came to light in July 2026. TechCrunch independently reports that HIBP obtained a copy of the breached dataset and counted more than 55.3 million affected people.

TechCrunch also reports that Suno had not publicly disclosed the breach or notified individuals at the time of its story. The outlet says a Suno spokesperson later confirmed that the company experienced a security incident in November 2025 and did not dispute the affected-user count.

The Register gives the same broad scale from HIBP and says the dump consisted mostly of email addresses, with phone numbers included for users who signed up that way. It also highlights the Stripe-related records as a narrower but more sensitive part of the corpus.

The leaked material reportedly went beyond account records. TechCrunch and The Register both connect the incident to claims that source code in the breach showed Suno scraping songs and lyrics from services such as YouTube, Deezer, and Genius to train AI models.

That claim is separate from the user-data risk and should be treated separately. It matters because Suno is already facing copyright litigation from major record labels over AI training practices. For LinkLoot readers, the security takeaway is simpler: AI creator platforms can hold both ordinary account data and commercially sensitive workflow data, while also sitting inside active legal disputes.

What teams should verify now

Teams using Suno for marketing, social clips, podcast stingers, or creator workflows should check whether shared team inboxes, contractor accounts, or brand-owned phone numbers appear in breach-monitoring tools. If a card was used for Suno purchases, review Stripe or card-provider alerts for suspicious charges, even though the disclosed data does not include full card numbers.

Admins should also update internal guidance. A convincing phish could reference Suno usage, a real payment amount, an address, or the current AI-music copyright debate. That makes a generic "reset your password" warning too weak; users need to know what context an attacker may already have.

Evidence

The primary record is Have I Been Pwned's Suno breach entry, which lists the breach timing, more than 55 million unique email addresses, phone-number exposure, and the Stripe purchase-record fields. TechCrunch corroborates the scale, reports the company confirmation, and says Suno had not publicly disclosed the incident at publication time. The Register independently reports the same HIBP scale and summarizes the exposed data categories.

The strongest unresolved question is notification. Until Suno publishes its own user-facing incident notice, affected users should rely on breach-monitoring checks and assume targeted phishing is the near-term risk.