Suno Data Breach (July 2026)
A breach at the AI music generator in November 2025 came to light in July 2026, and Have I Been Pwned verified 55.3 million email addresses, with names, addresses and partial card details for the customers who had paid.
- Organization
- Suno
- Sector
- Technology
- Country
- United States, MA
- Incident date
- November 25, 2025
- Disclosed
- July 20, 2026
- Records affected
- 55.3 million
- Attack type
- Undisclosed
- Status
- Confirmed
- Email addresses
- Phone numbers
- Names
- Physical addresses
- Purchases
- Partial credit card data
- The breach occurs, per the date Have I Been Pwned records for the data
- Have I Been Pwned loads 55.3 million verified email addresses; the incident becomes public
- Suno confirms the incident and says it is notifying affected users, per reporting relayed by Secarma
- The first class action is filed against Suno
What Happened
Suno, the Cambridge, Massachusetts company behind one of the most widely used AI music generators, suffered a data breach in November 2025 that did not come to light until July 2026, according to the Have I Been Pwned entry. The verified data holds more than 55 million unique email addresses, which makes it one of the largest breaches of the year by that measure.
Suno confirmed the incident and said it was notifying affected users, per reporting from TechCrunch relayed by Secarma. The company has not said how the attackers got in, so the attack type is recorded as undisclosed. Class actions followed within days of the disclosure.
What was Exposed
For most accounts: the email address, and a phone number where one was used to sign up. For a much smaller group, the paying customers: tens of thousands of Stripe records covering purchases, with names, physical addresses, purchase amounts and partial card data consisting of the card type, the expiry date and the last four digits. Per Have I Been Pwned, Suno said it does not have access to customers' full card numbers in Stripe, so full card numbers were not part of what could be taken.
The gap between the incident in November and the disclosure in July matters. For eight months, the addresses were in circulation with nobody in the set knowing to be careful, which is the situation the breach notification laws exist to prevent.
What to do if you are Affected
Partial card data cannot be used to charge a card on its own, but it makes a scam call far more convincing: "this is your bank, we see a charge from Suno on the card ending 4412" is exactly the script the data enables.
The full order of operations is in what to do after a data breach, and the scripts to expect are in what phishing looks like.
What is not Known Yet
How the attackers got in, why the incident took eight months to surface, and what Suno's own notice to users says about the payment records. The report will be updated when the company or a court filing adds to the record.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.