Suno breach: 55.3M users, disclosed eight months late
A November 2025 breach at AI music generator Suno surfaced in July 2026 via Have I Been Pwned. Your AI vendor controls your disclosure timeline.
The Suno breach is a useful reminder that when you sign up for an AI tool, you hand a stranger a slice of your customer data and give up control of when you find out it leaked. Have I Been Pwned added Suno to its breach index on July 20, 2026 — 55.3 million accounts, from an incident dated November 2025. That's eight months between the intrusion and the day users could learn about it, and they learned about it from a third-party notification service.
What actually happened
TechCrunch reports the stolen data includes names, physical addresses, email addresses, phone numbers, purchase history, and partial payment card numbers with expiry dates pulled from the company's Stripe account. The attacker also took Suno's source code. The HIBP entry lists 55.3M pwned accounts, breach date November 2025, added July 20, 2026.
Suno had not posted a disclosure on its site or notified users. After TechCrunch published, a spokesperson confirmed the November 2025 incident and did not dispute the affected-user count, but produced no documentation that users were ever notified. The story surfaced through 404 Media's reporting and the HIBP dataset, not the company.
There's a second-order sting: the stolen source code reportedly shows how Suno sourced training material from Deezer, Genius, and YouTube — a detail now landing in the middle of active copyright litigation against the company. A breach doesn't just expose your customers. It exposes how the vendor actually operates.
Why vendor breach disclosure matters for your business
Most small businesses run 20–40 SaaS and AI tools nobody has inventoried. Each one holds something: emails, order history, card fragments, support transcripts. If one of them sits on an incident for eight months, your breach-notification clock — the one you owe your customers and, depending on your state, your regulator — starts whenever the vendor decides.
You can't fix your vendors' disclosure ethics. You can shrink the blast radius. Keep a written list of every tool that touches customer PII and what fields it holds. Use a unique, aliased email per vendor so you can trace a leak back to its source. Never reuse credentials across a marketing toy and your payment stack. Monitor your domain in HIBP so a third party isn't the last to tell you. And read the incident-notification clause in your vendor contracts before you sign — "promptly" is not a deadline.
Key takeaways
- HIBP added Suno on July 20, 2026: 55.3M accounts, breach dated November 2025
- Exposed data includes names, addresses, emails, phones, purchase history, and partial card numbers with expiry dates
- Suno had not publicly disclosed or notified users; it confirmed the incident only after press inquiry
- Inventory which AI tools hold your customer PII, alias vendor emails, and put a notification deadline in writing
Can you name every tool that holds your customer data? Most operators can't, which is exactly why a vendor breach turns into a two-week fire drill. We map the data surface across your stack and cut the tools that don't earn their access. See how we work.
Sources: TechCrunch, Have I Been Pwned.
- #security
- #data-breach
- #vendor-risk
- #ai-tools
- #compliance
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Cursor's ₹649 India tier: dev seats go geographic
Cursor launched a ₹649/month India-only plan, roughly a third of its $20 Pro tier. AI dev tool pricing is now segmented by market, and that changes your budget math.
Read itvBulletin RCE exploit went public: get to 6.2.2 today
A working exploit for vBulletin CVE-2026-61511 dropped four weeks after the patch. Unauthenticated remote code execution, no in-the-wild reports yet. That window closes fast.
Read it