The AI music generator Suno suffered a significant security breach, according to a report from 404 Media. The incident, which occurred in November 2025, exposed internal source code revealing that the company allegedly scraped decades of audio content from YouTube Music, Deezer, Genius, various stock music libraries, and podcast RSS feeds to train its models.
How the Breach Uncovered Suno’s Data Tactics
The hacker responsible for the intrusion explained that they executed a supply chain attack to compromise an employee’s credentials. This unauthorized access granted them entry to internal source code, which directly contradicts the company’s previous public statements regarding its data acquisition methods. While Suno has previously admitted to training its AI on “publicly available music files,” they have consistently defended the practice under the fair use doctrine.
Legal Battles and Copyright Allegations
Major record labels currently suing Suno argue that the company’s actions are illegal under the Digital Millennium Copyright Act (DMCA). The core of the legal argument is that Suno deliberately circumvented YouTube’s protective measures against data scraping, which also constitutes a direct violation of YouTube’s terms of service.
The industry scrutiny extends beyond Suno. Its competitor, Udio, faces similar accusations regarding the scraping of YouTube audio. Meanwhile, Google, YouTube’s parent company, is navigating its own copyright infringement allegations brought by various book publishers.
Customer Data Exposure and Company Response
Beyond the exposure of training methodologies, the hacker reportedly accessed sensitive customer information, including customer emails, phone numbers, and partial credit card numbers processed via Stripe.
Suno did not notify its user base regarding the November 2025 breach. The company maintains that the event was a “limited security incident that was quickly contained.”
