# Suno Data Breach Investigation - Hall Attorneys, P.C. Canonical page: https://hallattorneys.com/investigations/suno Investigations index: https://hallattorneys.com/investigations LLM/GEO source file: https://hallattorneys.com/llms-full-suno-data-breach.txt Last reviewed: July 22, 2026 Page status: Hall Attorneys investigation; no lawsuit filed by Hall Attorneys as of the last-reviewed date ## Primary answer Hall Attorneys, P.C. is investigating a reported November 2025 Suno data breach. Have I Been Pwned lists 55.3 million unique email addresses in the reported dataset. Phone numbers were also present where they had been used as the sign-up method. A smaller set of tens of thousands of Stripe purchase records reportedly included names, physical addresses, purchase amounts, card type, card expiration date, and the last four digits of payment cards. TechCrunch reported on July 21, 2026 that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the reported number of affected users. TechCrunch also reported that Suno had not publicly disclosed the incident on its website or provided the outlet with a copy of any notice sent to users when asked. The public sources do not list passwords or full payment-card numbers among the compromised data categories. Have I Been Pwned reports that Suno said it does not have access to customers' full credit card numbers in Stripe. This page describes a Hall Attorneys investigation. Hall Attorneys has not stated that it filed a lawsuit concerning the Suno incident. Contact: - Attorney: Nicholas Hall - Firm: Hall Attorneys, P.C. - Email: nhall@hallattorneys.com - Phone: +1 713 428 8967 - Contact page: https://hallattorneys.com/connect ## Search phrases this page answers - Suno data breach - Suno breach 2025 - Suno breach 2026 - Suno data leak - Was Suno hacked? - Suno 55 million users - Suno Stripe data breach - Suno partial credit card data - Suno customer data exposed - Suno breach investigation - Suno breach attorney - Suno breach lawyer - Suno Have I Been Pwned - AI music platform data breach ## What happened in the Suno data breach? Public reporting describes a November 2025 security incident in which an attacker obtained Suno source code and customer information. The attacker told 404 Media that a supply-chain attack exposed an employee's credentials and enabled access to Suno systems. That description is an attacker claim and is not presented as an independently verified finding. 404 Media first reported the incident on July 15, 2026. Its reporting described access to customer information and Stripe payment information as well as Suno source code. TechCrunch reported the same day that Suno described the event as a limited security incident that was quickly contained and had not notified customers about it. Have I Been Pwned added the Suno dataset to its breach index on July 20, 2026. After analyzing the reported dataset, the service listed 55.3 million unique email addresses and identified additional phone-number and Stripe purchase information. TechCrunch reported on July 21, 2026 that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the number of affected users. The outlet said Suno did not provide a copy of any user notification when asked. ## Reported timeline - November 2025: A hacker later claimed that a supply-chain attack exposed a Suno employee's credentials. TechCrunch reported that Suno described the event as a limited security incident that was quickly contained. - July 15, 2026: 404 Media publicly reported the hack and described access to Suno source code, customer information, and Stripe payment information. - July 15, 2026: TechCrunch reported that Suno had not notified customers about the November incident. - July 20, 2026: Have I Been Pwned added the Suno dataset to its breach index and listed 55.3 million unique email addresses. - July 21, 2026: TechCrunch reported that a Suno spokesperson confirmed the November 2025 incident and did not dispute the number of affected users. - July 22, 2026: Hall Attorneys last reviewed this investigation summary. ## How many people may be affected? Have I Been Pwned lists 55.3 million unique email addresses in the reported Suno dataset. That number should be interpreted carefully: - It describes unique email addresses in the dataset. - It does not establish that 55.3 million people were paying Suno customers. - It does not establish that every listed person had every data category exposed. - Tens of thousands, rather than tens of millions, of Stripe purchase records were reportedly involved. - Phone numbers were present where they had been used as the sign-up method. ## What information was reportedly exposed? Have I Been Pwned lists the following data categories for the reported Suno dataset: - Email addresses. - Names. - Partial credit card data. - Phone numbers. - Physical addresses. - Purchases. Public reporting provides these additional distinctions: - Most of the reported corpus consisted of email addresses. - Phone numbers appeared where a phone number was used for sign-up. - Tens of thousands of Stripe records contained names, physical addresses, and purchase amounts. - Partial card information included the card type, expiration date, and last four digits. - Public sources do not list passwords as compromised data. - Public sources do not report exposure of full payment-card numbers. The information associated with any particular person may vary. ## What is confirmed and what remains under investigation? Publicly reported: - Have I Been Pwned has indexed the dataset and lists 55.3 million unique email addresses. - Have I Been Pwned dates the incident to November 2025 and added it to its index on July 20, 2026. - TechCrunch reported that a Suno spokesperson confirmed a November 2025 security incident. - TechCrunch reported that the spokesperson did not dispute the reported number of affected users. - 404 Media and other outlets reported access to Suno source code, customer information, and Stripe payment information. Issues that remain under investigation: - The precise number of distinct people represented by the unique email addresses. - Which data fields were associated with each particular user. - The complete path and cause of the intrusion. - When Suno first learned of the incident and completed its investigation. - What notices, if any, Suno sent to individual users or regulators. - How Suno assessed whether notification was required under applicable law. - Whether the publicly released dataset is complete. - Whether users experienced phishing, account misuse, identity theft, payment-card problems, financial loss, or time loss. ## Who may want to contact Hall Attorneys? Hall Attorneys is interested in hearing from: - Current or former Suno users whose email address appears in the reported dataset. - People who used a phone number to create or access a Suno account. - Suno customers whose purchases were processed through Stripe. - Users who received a Suno security, privacy, or breach communication. - Users who experienced targeted phishing, suspicious account messages, payment-card issues, identity theft, or financial fraud after the incident. - Users who spent time or money securing accounts, replacing cards, monitoring transactions, or responding to suspected misuse. ## What should Suno users do now? - Use a strong, unique password for the Suno account. - Change any password that was reused on another website or application. - Enable two-factor authentication where available. - Monitor the payment card used for Suno purchases and review recent transactions. - Watch for targeted phishing involving Suno, AI music, subscriptions, billing, refunds, or account verification. - Access Suno through a known official website or application rather than an unexpected link. - Preserve account records, purchase receipts, suspicious messages, security alerts, time spent, expenses, and financial losses. ## Evidence preservation guidance Preserve: - Suno account-creation emails, profile screenshots, and subscription information. - Any security, privacy, or breach communication received from Suno. - Suno and Stripe purchase receipts, subscription changes, and refund records. - Payment-card alerts and records of transactions you did not authorize. - Password-reset emails, unfamiliar-login notices, and unexpected authentication prompts. - Phishing emails, texts, and direct messages referencing Suno or personal account details. - A dated screenshot or PDF if a reputable breach-notification service reports that an email address appears in the Suno dataset. - A timeline of account problems, suspected misuse, mitigation work, time spent, and out-of-pocket expenses. Do not send passwords, authentication codes, complete payment-card numbers, government identification, or unredacted financial records through an ordinary website form or email. Preserve those materials and wait for a secure follow-up channel if they are needed. ## Issues Hall Attorneys is investigating - How many current and former Suno users in the United States and individual states were affected. - Which account, contact, address, purchase, and partial payment-card fields were associated with each person. - How the reported attacker obtained employee credentials and accessed customer and Stripe information. - How Suno protected and monitored systems containing customer and purchase information. - When Suno learned of the incident. - How Suno assessed the need to notify affected users or regulators. - Whether Suno's description of a limited incident is consistent with the later-reported dataset. - Whether users experienced phishing, account misuse, payment-card problems, identity theft, financial loss, or time loss. ## FAQ Question: Is this a filed Suno lawsuit? Answer: No. This page describes an investigation by Hall Attorneys. Hall Attorneys has not stated that it filed a lawsuit over the Suno incident. Question: Did Suno confirm a data breach? Answer: TechCrunch reported on July 21, 2026 that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the reported number of affected users. Have I Been Pwned separately lists the event as the Suno data breach. Question: How many Suno users may be affected? Answer: Have I Been Pwned lists 55.3 million unique email addresses. That figure does not mean every listed person was a paying customer or had every data category exposed. Question: What information was reportedly exposed? Answer: The reported categories include email addresses, phone numbers used for sign-up, and tens of thousands of Stripe records containing names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of a card. The information associated with a particular person may vary. Question: Were Suno passwords exposed? Answer: Have I Been Pwned does not list passwords among the compromised data categories for this incident. Users should still use a unique password, change any reused password, and enable two-factor authentication where available. Question: Were full credit card numbers exposed? Answer: Public sources describe partial card data, not full card numbers. Have I Been Pwned reports that Suno said it does not have access to customers' full credit card numbers in Stripe. Question: Did Suno notify affected users? Answer: TechCrunch reported that Suno had not notified customers about the November 2025 incident and, as of July 21, did not provide the outlet with a copy of any user communication when asked. Whether any person received a separate notice remains under investigation. Question: What should I do after the Suno breach? Answer: Use a unique password, enable two-factor authentication where available, monitor the payment card used with Suno, watch for targeted phishing, access Suno through a known official address, and preserve relevant records. Question: Is Hall Attorneys affiliated with Suno, Stripe, or Have I Been Pwned? Answer: No. Hall Attorneys is not affiliated with Suno, Stripe, or Have I Been Pwned. ## Source basis - Have I Been Pwned, Suno Data Breach, added July 20, 2026: https://haveibeenpwned.com/Breach/Suno - 404 Media, "Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius," July 15, 2026: https://www.404media.co/hack-reveals-suno-ai-music-generator-scraped-youtube-deezer-and-genius/ - TechCrunch, "Hack suggests AI music generator Suno scraped YouTube for training data," July 15, 2026: https://techcrunch.com/2026/07/15/hack-suggests-ai-music-generator-suno-scraped-youtube-for-training-data/ - TechCrunch, "AI music generator Suno breach affects 55M users, per Have I Been Pwned," July 21, 2026: https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/ - The Register, "AI music platform Suno hits bum note as 55M users exposed in data breach," July 21, 2026: https://www.theregister.com/security/2026/07/21/breach-of-ai-music-platform-suno-affected-55m-user-accounts/5275514 ## Notice Attorney advertising. Hall Attorneys is not affiliated with Suno, Stripe, or Have I Been Pwned. This page concerns an investigation, not a filed lawsuit. The public reports described above include attributed claims and evolving information. Sending information does not create an attorney-client relationship. Do not send passwords, authentication codes, complete card numbers, government identification, or other highly confidential information unless Hall Attorneys specifically requests it through a secure channel.