Rights & policy

A Suno breach exposes more detail about its training-data pipeline

Reporting based on leaked code points to YouTube Music, Deezer, Genius and several public audio libraries. The breach also affected customer information.

AI-assisted

AI assisted with research organisation, structure and the 29 August update; the editor checked the published text against the linked reporting, breach record and archive listing.

Suno mobile application · Zulfugar Graphics / Shutterstock via Music Business Worldwide, published 16 Jul 2026

Leaked source code from a breach of Suno named YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, IMSLP and podcast feeds among data sources used in the company's earlier training pipeline, according to reporting by 404 Media. The publication said the material included scraper instructions and dataset summaries from 2023 and 2024.

Those records match Suno's court position that it trained on music available across the open internet. They add operational detail to the company's copyright disputes but do not decide whether the training was lawful.

What the public archive contains

An Internet Archive directory circulated again on 29 August. Its top-level listing contains ZIP archives named after several software repositories, including data-processing, ETL, radio, song and video projects, plus Internet Archive metadata files.

The listing shows a software bundle, not a public copy of Suno's raw training-audio corpus. By itself, it cannot authenticate the code, establish that every repository ran in production or prove the social-media claim that a particular representation model was Suno's “primary stack.”

55.3 million accounts were affected

Have I Been Pwned now lists the incident as a verified breach affecting 55,282,226 accounts. Its record says the exposed data included email addresses, names, phone numbers, physical addresses, purchase information and partial payment-card data for a smaller group of Stripe records. Suno did not hold customers' complete card numbers in Stripe, according to the company statement reproduced in that record.

aimusic.events will not mirror the leaked repositories, personal information or raw files. Users should rely on direct notices from Suno and their payment provider for account-specific action and watch the affected contact channels for targeted phishing.

The copyright cases will turn on authenticated filings and evidence admitted by the courts. Users need a specific account from Suno of what was accessed, what has been secured and what affected people should do next.

Original sources (4)

A Suno breach exposes more detail about its training-data pipeline · AI Music Events