Suno Data Breach Exposes 55M Email Addresses and Partial Payment Records
Key Takeaways
- ▸55 million unique email addresses compromised in November 2025 breach, publicly disclosed in July 2026
- ▸Partial payment card data and customer personal information (names, addresses) exposed; full credit card numbers were not stored or compromised
- ▸Affected users should immediately change passwords and enable two-factor authentication across all accounts
Summary
AI music generation platform Suno disclosed a significant data breach affecting over 55 million unique email addresses, which occurred in November 2025 but wasn't revealed until July 2026. The compromised data included phone numbers used for account registration, as well as partial payment information from tens of thousands of Stripe transactions.
The breach exposed customer names, physical addresses, purchase amounts, and partial credit card details including card type, expiry dates, and the last four digits of cards. However, Suno clarified that full credit card numbers were not compromised, as the company does not retain complete card information in its systems. The delayed disclosure, occurring eight months after the incident, raises questions about breach detection and notification timelines.
Security researchers and privacy advocates recommend that affected users immediately change passwords on any accounts where breached credentials were reused, and enable two-factor authentication wherever available. The incident highlights ongoing vulnerabilities in AI company data infrastructure and the importance of adopting password managers and multi-factor authentication to mitigate risks from future breaches.
- Eight-month gap between breach and disclosure raises concerns about incident response and notification practices



