Skip to content
Rush Commerce
Software & Dev3 min read

Suno breach: 55.3M users, disclosed eight months late

A November 2025 breach at AI music generator Suno surfaced in July 2026 via Have I Been Pwned. Your AI vendor controls your disclosure timeline.

The Suno breach is a useful reminder that when you sign up for an AI tool, you hand a stranger a slice of your customer data and give up control of when you find out it leaked. Have I Been Pwned added Suno to its breach index on July 20, 2026 — 55.3 million accounts, from an incident dated November 2025. That's eight months between the intrusion and the day users could learn about it, and they learned about it from a third-party notification service.

What actually happened

TechCrunch reports the stolen data includes names, physical addresses, email addresses, phone numbers, purchase history, and partial payment card numbers with expiry dates pulled from the company's Stripe account. The attacker also took Suno's source code. The HIBP entry lists 55.3M pwned accounts, breach date November 2025, added July 20, 2026.

Suno had not posted a disclosure on its site or notified users. After TechCrunch published, a spokesperson confirmed the November 2025 incident and did not dispute the affected-user count, but produced no documentation that users were ever notified. The story surfaced through 404 Media's reporting and the HIBP dataset, not the company.

There's a second-order sting: the stolen source code reportedly shows how Suno sourced training material from Deezer, Genius, and YouTube — a detail now landing in the middle of active copyright litigation against the company. A breach doesn't just expose your customers. It exposes how the vendor actually operates.

Why vendor breach disclosure matters for your business

Most small businesses run 20–40 SaaS and AI tools nobody has inventoried. Each one holds something: emails, order history, card fragments, support transcripts. If one of them sits on an incident for eight months, your breach-notification clock — the one you owe your customers and, depending on your state, your regulator — starts whenever the vendor decides.

You can't fix your vendors' disclosure ethics. You can shrink the blast radius. Keep a written list of every tool that touches customer PII and what fields it holds. Use a unique, aliased email per vendor so you can trace a leak back to its source. Never reuse credentials across a marketing toy and your payment stack. Monitor your domain in HIBP so a third party isn't the last to tell you. And read the incident-notification clause in your vendor contracts before you sign — "promptly" is not a deadline.

Key takeaways

  • HIBP added Suno on July 20, 2026: 55.3M accounts, breach dated November 2025
  • Exposed data includes names, addresses, emails, phones, purchase history, and partial card numbers with expiry dates
  • Suno had not publicly disclosed or notified users; it confirmed the incident only after press inquiry
  • Inventory which AI tools hold your customer PII, alias vendor emails, and put a notification deadline in writing

Can you name every tool that holds your customer data? Most operators can't, which is exactly why a vendor breach turns into a two-week fire drill. We map the data surface across your stack and cut the tools that don't earn their access. See how we work.

Sources: TechCrunch, Have I Been Pwned.

  • #security
  • #data-breach
  • #vendor-risk
  • #ai-tools
  • #compliance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.