Suno Breach: 55M Accounts - Emails & Credit Cards (2026)
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of th...
Overview
In July 2026, AI music generation startup Suno disclosed a data breach that actually occurred in November 2025 - but only came to light after a third party contacted affected users. The breach compromised over 55 million unique email addresses, along with names, phone numbers, and physical addresses. Most critically, tens of thousands of Stripe payment records were also exposed, containing partial credit card data including card type, expiration date, and last four digits. The breach was reported to Have I Been Pwned, and affected users can check at haveibeenpwned.com.
What Was Exposed
The breach is a multi-layered data dump, with the vast majority being email addresses used for account creation. However, the inclusion of payment records makes this incident significantly more dangerous. The exposed data falls into two categories:
- Core account data: Over 55 million email addresses, plus names and phone numbers (where used for sign-up).
- Payment records: Tens of thousands of Stripe records containing names, physical addresses, purchase amounts, and partial credit card data - the card type, expiration date, and last four digits. Suno has stated it “does not have access to customers’ full credit card numbers in Stripe.”
Identity Theft Risks
While full credit card numbers were not exposed, partial card data is valuable to attackers. With the last four digits, expiration date, and card type, threat actors can:
- Combine this data with other breached credentials for targeted phishing attacks
- Use it to bypass some two-factor authentication systems that ask for the last four digits
- Craft convincing fake payment verification messages to trick victims into revealing full card details
The presence of names, addresses, and phone numbers alongside payment data makes this a goldmine for identity theft. Attackers have everything they need to impersonate companies like Suno, banks, or payment processors to extract additional sensitive information.
How the Breach Happened
Suno has not publicly disclosed the specific attack vector. The eight-month gap between the breach and disclosure - from November 2025 to July 2026 - suggests the company may not have initially detected the intrusion, or chose to delay public notification until law enforcement or forensic investigations were complete. This extended dwell time is concerning in the cybersecurity news landscape, where prompt disclosure is critical for limiting damage.
Account Takeover Risks
Email addresses are the most common credential for online accounts. With over 55 million email addresses now public, attackers will use them to:
- Launch credential-stuffing attacks against Suno accounts and other services
- Send highly targeted phishing emails that reference the Suno breach
- Attempt password resets on linked accounts (banking, social media, email)
The breach also exposed phone numbers, which attackers can use to social-engineer mobile carriers into swapping SIMs, bypassing SMS-based two-factor authentication.
What to Do Right Now
- Check if you’re affected: Visit haveibeenpwned.com and search for your email address. If it appears in the Suno breach, follow the steps below.
- Change your Suno password immediately - and use a unique, strong password you have not reused elsewhere. Enable two-factor authentication on your Suno account if available.
- Monitor your credit card statements for unauthorized transactions. Even though full card numbers weren’t exposed, partial data can be used in fraud attempts.
- Be alert for phishing emails that mention Suno or reference the breach. Attackers will use the exposed data to make their messages look legitimate.
- Update passwords on any other accounts where you used the same email and password combination as Suno.
How to Check If You’re Affected
The breach is indexed on Have I Been Pwned. Simply visit the site, enter your email address, and it will tell you if your data was part of the Suno leak. If you used your phone number as your sign-up method, you may need to check using the email address linked to that Suno account.
Security Insight
This breach reveals a troubling pattern: Suno held onto customer data - including payment records - for at least eight months without detecting the intrusion. For a company generating revenue through subscriptions and purchases, failing to monitor access to Stripe payment data is a serious oversight. It highlights how AI startups, often focused on rapid growth and feature development, can neglect fundamental security hygiene - such as segmenting payment data from core account databases and implementing real-time breach detection.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone nu...
In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partia...
In February 2026, a data breach allegedly containing data relating to Canada Goose customers was published publicly . The data contained 920k records with 582k unique email addresses and included names, phone numbers, IP addresses, physical addresses and partial credit card data, specifically card t...
In April 2026, home security firm ADT confirmed a data breach by ShinyHunters , which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a sm...