Have I Been Pwned, the breach notification service operated by Troy Hunt, ingested a copy of the stolen dataset and confirmed it covers 55.3 million user accounts. The count is the first independent verification of the intrusion's scale, according to theregister.com, whose 21 July 2026 report frames the disclosure as HIBP "confirming scale for first time."
The bulk of the dump is email addresses, with phone numbers attached where users registered with a mobile number instead of an email login. Layered on top are tens of thousands of records pulled from Suno's Stripe payment account: customer names, physical addresses, purchase amounts, and partial card data limited to card type and expiry dates rather than full primary account numbers. techcrunch.com lists the same fields in its 21 July 2026 report.
That mix of fields is enough for targeted phishing on its own. The Stripe-derived data adds a billing layer that turns account-takeover attempts into plausible fraud campaigns, with names and physical addresses doing the social-engineering work and partial card metadata anchoring the pitch. The dataset's commercial value sits in the pairing.
The attacker gained access in November 2025, eight months before the scale became public. The intrusion surfaced earlier in July 2026 when 404 Media reported that hackers had obtained both source code and user data from Suno, after which HIBP ingested the file and verified the account count. The reporting order across the week ran 404 Media first, HIBP second, then mainstream outlets picking up the verified count.
Suno had not, as of late July 2026, issued a formal breach notification to affected users. rescana.com's 23 July 2026 analysis states the company has not disclosed the incident to its user base, leaving 55.3 million people to learn of their exposure only if they check HIBP themselves or follow the press.
That gap — compromise in November 2025, public disclosure in July 2026 — is the operational story. HIBP's role is forensic, not regulatory; it confirms what was taken, it does not compel Suno to tell the people whose data was taken. The published dates of the major coverage cluster on 21 July 2026, with follow-on analysis on 22 and 23 July.
The exfiltrated source code revealed that Suno had been scraping music and podcasts from major platforms, a detail that turns the breach from a privacy event into an IP story. rescana.com describes the exfiltration as exposing "details about Suno's AI training practices," phrasing that points at inputs and data pipelines rather than model weights or inference code. That distinction matters: training-data provenance is the legally combustible part.
That is a separate harm from the personal data theft, and the two harms do not share a remediation path. A breach that exposes payment metadata is a privacy event with notification obligations; a breach that also exposes training-source code is an IP and copyright-liability event, and the rescana.com summary notes the incident has intensified scrutiny of "data governance and copyright compliance within the AI and music technology sectors." Rights-holders now have a public artifact — the source code — they can use to argue infringement at scale.
What Suno's eight-month silence on disclosure reflects is unclear from the public record. The plausible explanations are ongoing forensic work, a legal hold, or a calculation that notification costs more than the regulatory exposure in the jurisdictions where its users sit; the evidence does not distinguish between them, and Suno has not, on the record, offered one.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.