In the long and unresolved negotiation between human creativity and machine learning, a security breach at Suno has made visible what was once only implied: that the AI music generator built its generative capacity on hundreds of thousands of hours of music drawn from platforms that never consented to the arrangement. The hack, reported in mid-July 2026, exposed not only the architecture of that data collection but also the personal information of Suno's own customers, arriving at a moment when the company is already contesting copyright lawsuits from the music industry's most powerful institu
Suno Hack Exposes How AI Music Generator Scraped Millions of Songs
Systematic data collection from platforms that did not consent to it
So Suno knew it was scraping music from these platforms. Why is the hack significant if they've already admitted to training on internet music?
Because admission and documentation are different things. Suno said it trained on "publicly available music" — that's vague. The code shows exactly which platforms, exactly how much, exactly how they filtered it. That specificity matters in a courtroom.
The company says the exposed code is outdated. Do we know if they're still scraping the same way?
We don't. But the timing is what matters. This code was live as recently as November 2025. That's recent enough that it probably reflects their current practices, even if they claim otherwise.
What about the customer data exposure? That seems like the more immediate problem.
It is, for the users affected. But Suno is betting that because they don't store full credit card numbers, the damage is contained. They're probably right, legally. The bigger story is what the breach reveals about their training process.
Why would they not use artist names in training if they're trying to create original music?
That's their defense against the copyright suits. They're saying: we trained the model to understand music structure and style, not to memorize and reproduce specific artists. Whether a judge believes that when you've scraped 113,000 hours of YouTube Music is the open question.
Warner settled. Why didn't the others?
Warner saw an opportunity to work with Suno and shape the technology. Universal and Sony decided to fight. The breach might have just made that fight a lot easier for them.
O Pulso
- A hacker breached Suno's systems in November 2025 and walked away with source code revealing the company scraped over 113,000 hours of music from YouTube Music, Deezer, Genius, and other platforms — none of which consented to the arrangement.
- Customer emails, phone numbers, and Stripe payment data were also exposed, though Suno insists no full credit card numbers were taken and says the breach was contained quickly enough that it felt no obligation to notify users.
- The leaked code transforms the copyright battle from abstract legal theory into documented evidence: specific platforms, specific quantities, specific filters designed to harvest music at industrial scale.
- Universal Music Group, Sony Music, and the RIAA — already in active litigation against Suno — now have granular proof to challenge the company's fair use defense, while Warner Music Group, which settled separately, continues building a partnership with the company.
- Suno maintains the exposed code is outdated and no longer in use, and that its scraping of publicly available files falls within legal bounds — a position that will now face far sharper scrutiny in court.
In the long and unresolved negotiation between human creativity and machine learning, a security breach at Suno has made visible what was once only implied: that the AI music generator built its generative capacity on hundreds of thousands of hours of music drawn from platforms that never consented to the arrangement. The hack, reported in mid-July 2026, exposed not only the architecture of that data collection but also the personal information of Suno's own customers, arriving at a moment when the company is already contesting copyright lawsuits from the music industry's most powerful institutions. What was once a philosophical dispute about fair use has become, through leaked code and documented datasets, a concrete record of systematic appropriation.
A security breach at Suno has done what years of legal filings could not: it has made the company's training practices legible in precise, documented detail. According to a report by 404 Media based on data provided by a hacker, Suno's source code reveals the company systematically pulled music from YouTube Music, Deezer, Genius, Freesound, Jamendo, and the International Music Score Library Project, among others. The numbers embedded in the leaked files are striking — over two million clips from YouTube Music alone, and a total exceeding 113,000 hours of audio across platforms.
The same breach exposed Suno's customer database, including email addresses, phone numbers, and Stripe payment information. The company says it discovered the intrusion in November 2025, contained it quickly, and was not obligated to notify users given the breach's limited scope. It also notes that full credit card numbers were never stored. A spokesperson reiterated that Suno has always trained on publicly available music files and related metadata — a position the company has maintained in its legal filings.
That legal context is what gives the breach its sharpest edge. Universal Music Group, Sony Music Entertainment, and the RIAA have all filed copyright infringement suits against Suno, which has defended itself on fair use grounds, pointing to safeguards that prevent users from replicating specific songs or invoking artist names as prompts. Warner Music Group settled its own suit and is now collaborating with Suno on a new product. But for the labels still in litigation, the leaked code offers something they previously lacked: a concrete, quantified record of what was taken, from where, and by design — turning a theoretical argument about the boundaries of fair use into a documented case for systematic appropriation.
A security breach at Suno has pulled back the curtain on exactly how the AI music generator built its product: by systematically scraping millions of songs from YouTube Music, Deezer, Genius, and a half-dozen other music platforms and libraries, according to a report published Wednesday by 404 Media based on data provided by a hacker.
The company had always been transparent, in a broad sense, that it trained on music available across the internet. But the leaked source code tells a far more granular story. The instructions embedded in Suno's codebase show the company pulled from YouTube Music, Deezer, Genius, Freesound, Jamendo, and the International Music Score Library Project, among others. The code was designed to filter out anything that wasn't music. The same breach also gave the hacker access to Suno's customer database, which contained email addresses, phone numbers, and Stripe payment information.
The scale is staggering when you look at the actual numbers. One dataset file documented 2,013,545 music clips pulled from YouTube Music alone. Another file's comments broke down the training data in hours: 113,879 hours from YouTube Music, 17,615 hours from Genius, 12,287 hours from Deezer, 19,514 hours from the International Music Score Library Project, and smaller amounts from Freesound, Jamendo, and other sources. In total, the documents show Suno trained on hundreds of thousands of hours of music.
Suno's response has been measured. A company spokesperson said the breach was contained quickly after the company discovered it in November 2025, and that the exposed code was outdated and no longer in use. The company also stated that no full credit card numbers were compromised because it doesn't retain them, and that the limited nature of the breach meant it didn't feel obligated to notify users. "As we have stated in public filings and disclosures, Suno's AI models have been trained on publicly available music files and related metadata accessible on third-party websites on the open Internet," the spokesperson said.
But the hack arrives at a moment when Suno is already under legal siege. Universal Music Group, Sony Music Entertainment, and the Recording Industry Association of America have all filed copyright infringement lawsuits against the company. Suno has defended itself by arguing that its use of the training data falls under fair use protections, and that it has built safeguards into its system to prevent users from simply recreating existing songs. The company says it intentionally excludes artist names from its training metadata and has built filters that block users from using specific artist, song, or album names as prompts.
Warner Music Group took a different path, settling its lawsuit with Suno last year and now working with the company to develop a new version of the music generator. But the other major labels show no signs of backing down, and this breach gives them fresh ammunition. The detailed evidence of what was scraped, from where, and in what quantities, transforms what was once a theoretical argument about fair use into something far more concrete: a documented record of systematic data collection from platforms and services that did not consent to it.
Citações Notáveis
Our goal has always been to help people create original new music, not replicate someone else's. That's why we build our models around what we call 'Original Creation, By Design.'— Suno spokesperson
As we have stated in public filings and disclosures, Suno's AI models have been trained on publicly available music files and related metadata accessible on third-party websites on the open Internet.— Suno spokesperson