Skip to content
Live · Updated every 6 hours
Track every US data breachBreached
All breaches
CriticalReported Jul 21, 2026·From: HIBP
S
Data breach

Suno

Company archive

Suno, an AI music generation service, suffered a data breach in November 2025 that exposed over 55 million email addresses along with phone numbers, names, physical addresses, and partial credit card data from Stripe purchase records.

Reported
Jul 21, 2026
Breach date
Nov 25, 2025
People affected
55.3M
Severity
critical
What was exposed
Email addressesNamesPartial credit card dataPhone numbersAddressesPurchases

What happened

According to Have I Been Pwned, Suno's systems were breached in November 2025, though the incident only came to light in July 2026. The breach was later reported in connection with a hack that also revealed details about Suno's data sourcing practices.

What was exposed

The breach contained over 55 million unique email addresses. Phone numbers were included for accounts where a phone number had been used as the sign-up method. A smaller subset of the data consisted of tens of thousands of Stripe payment records, which included names, physical addresses, purchase amounts, and partial credit card details — specifically card type, expiry date, and last four digits. According to HIBP, Suno stated that it does not store or have access to customers' full credit card numbers in Stripe.

Who is affected

Anyone who created a Suno account is potentially affected, particularly those who signed up using a phone number or made purchases through the platform. The breach covers more than 55 million accounts in total.

What to do now

If you have a Suno account, monitor your email for phishing attempts and be cautious of unsolicited messages referencing your name or purchase history. If you used a phone number to sign up, be alert to SMS phishing. While full card numbers were not exposed, review your payment statements for any unfamiliar charges. Consider using a unique, strong password for Suno if you reuse passwords elsewhere, and enable two-factor authentication if available.