Suno Data Breach Investigation

Chimicles Schwartz Kriner & Donaldson-Smith is investigating potential class action claims against Suno, Inc. (“Suno”) on behalf of users of its AI music generation platform whose personal and financial information was compromised in a recently disclosed data security incident affecting more than 55 million user accounts.

What Happened?

Suno, one of the largest AI music generation platforms on the internet, suffered a data breach in November 2025 that was not publicly disclosed until July 2026, roughly eight months after the incident. According to recent reporting, a hacker operating under the handle “ellie.191” compromised a Suno employee through the Shai-Hulud npm supply-chain worm, harvesting GitHub tokens and cloud service credentials that allowed the attacker to access Suno’s private repositories, internal datasets, and customer records.

Suno has characterized the incident as a limited security incident that was quickly contained, and it has taken the position that the material exposed was outdated by source code that is no longer in use. Further, the Company stated that it did not notify its user base because it determined that formal notification was not legally required.

Who May Be Affected?

You may have been affected by this breach if you:

  • Created a Suno account at any point prior to November 2025
  • Signed up for Suno using an email address, phone number, or both
  • Purchased a Suno subscription, credit pack, or other paid product processed through Stripe
  • Received an alert from Have I Been Pwned indicating that your email address or phone number appeared in the Suno dataset
  • Otherwise believe your information was maintained by Suno as part of your use of the platform

What Information May Have Been Compromised?

According to recent reporting, the compromised data included the following categories of information:

    • Email addresses (over 55 million unique addresses)
    • Phone numbers (where used as the sign-up method)
    • Names
    • Physical addresses
    • Purchase amounts and purchase history
    • Partial payment card data (card type, expiration date, and last four digits)

Suno has represented that it does not retain full credit card numbers because payments are processed through Stripe.

Why Is This Important?

The reported combination of names, email addresses, phone numbers, physical addresses, purchase history, and partial payment card metadata is precisely the bundle of identifiers most commonly exploited for targeted phishing, SIM-swap and account-takeover attacks, “smishing” text scams, credential-stuffing against other online accounts, and payment-card enumeration and fraud. Because Suno users frequently sign up through Google, Microsoft, Discord, or Apple SSO, exposure of email addresses and phone numbers may also facilitate targeted social engineering against those third-party accounts.

What Should You Do?

If you created a Suno account, subscribed to Suno, or received a third party notification indicating that your email address or phone number appeared in the Suno dataset, you may have been affected by this incident. Please contact our data breach attorneys by completing the form below to learn more about your potential legal rights and our ongoing investigation.

Suno Data Breach (#943)

(*) Indicates required field: When communicating with us through this site or otherwise in connection with a matter for which we do not already represent you, your communication may not be treated as privileged or confidential, and does not create an attorney-client relationship between you and our Firm.