Tech News · 19 July 2026

Suno Hack Reveals AI Music App Scraped YouTube, Deezer and Genius

Leaked source code shared with 404 Media appears to show the AI music company collected millions of tracks and lyrics while customer data was also accessed.

Legacy article - classification pending

What you need to know

  • Source code shared with 404 Media appears to detail large-scale collection of music, lyrics and podcasts from several online services.
  • Suno confirmed a November 2025 security incident but said the compromised code was outdated and no sensitive personal information was taken.
  • The disclosure adds fresh evidence to major-label copyright cases over AI music training data.

Suno, the AI music-generation company, was breached in November 2025 in an incident that exposed internal source code and information linked to hundreds of thousands of customers, according to reporting by 404 Media. The company confirmed the security incident after the story emerged on 15 July 2026, when the hacker who accessed its systems shared material with journalist Jason Koebler.

Laptop with blurred code, headphones, phone and padlock on a desk
Suno says a November 2025 security incident was quickly contained, but the breach emerged publicly on 15 July 2026.

The leaked code appears to show that Suno collected millions of music clips and lyrics from YouTube Music, Deezer and Genius, alongside material from stock libraries and other online sources. It also suggests the company gathered a substantial catalogue of podcasts, intensifying the legal and ethical debate around the data used to train generative AI music systems.

Suno said it identified the breach at the time and contained it quickly. A spokesperson said:

“In November of 2025, we determined that Suno had been the subject of a limited security incident that was quickly contained. At the time, we immediately conducted an investigation and verified that the incident primarily involved outdated source code that is no longer in use at Suno.”

Code points to huge music datasets

According to the hacker and code reviewed by 404 Media, one file recorded the ingestion of “2,013,545 music clips” from YouTube Music. Comments in another file listed 113,879 hours of YouTube Music, 17,615 hours of Genius material, 12,287 hours of Deezer audio, 62,117 hours from Pond5 and 19,514 hours from the International Music Score Library Project.

The material also referenced Jamendo, Freesound, MuseScore lyrics and other datasets. Code apparently searched YouTube for acapella versions of songs, suggesting an effort to locate vocal recordings. Other code indicated Suno used proxy infrastructure from Bright Data while scraping YouTube.

Separate code reportedly trawled 420,000 podcasts in pursuit of roughly one million hours of speech. Pond5, a Shutterstock-owned stock-media library, says it has 2.5 million music tracks; the leaked data suggested Suno collected a significant portion of that catalogue, according to the report.

The apparent details are significant because Suno had previously acknowledged scraping “tens of millions of recordings” from the internet for training. In a 2024 court filing, it argued that this amounted to fair use under copyright law. What had not been publicly disclosed was the apparent scale of particular sources or the methods used to obtain the files.

New weight for the YouTube allegations

The code may also bolster claims made by the Recording Industry Association of America in an amended complaint against Suno in September 2025. The RIAA alleged that Suno had “stream ripping” recordings from YouTube and bypassed the platform’s rolling-cipher protection, a technical measure intended to prevent unauthorised downloading.

“Suno obtained those copies in the first instance by unlawfully ‘stream ripping’ them from the popular streaming platform YouTube, and circumventing the technological measures designed specifically to prevent such unauthorized copying,” the RIAA wrote in its lawsuit.

Suno is defending a copyright case brought by Universal Music Group and Sony Music Entertainment, co-ordinated by the RIAA. It maintains that training on copyrighted works can be protected by fair use. The case in Massachusetts federal court is now scheduled for dispositive motions on 9 April 2027.

Warner Music Group, once a co-plaintiff, settled with Suno in November 2025 and entered a licensing partnership that included Suno’s acquisition of Songkick. Rival AI music company Udio also settled with Warner and is moving towards a licensed platform.

Customer data was accessed, Suno says notifications were not required

The hacker also told 404 Media they accessed customer information including email addresses and/or phone numbers, plus Stripe payment details. The report said affected customers who spoke to the publication had not received breach notifications.

Suno said full card numbers were not involved and defended its decision not to contact customers individually.

“Importantly, Suno does not have access to customers’ full credit card numbers in Stripe.”

“Based on the limited nature of the customer information believed to be involved, we determined that individual notifications were not warranted under applicable privacy laws,” the spokesperson said.

Every US state has a breach-notification law, while Massachusetts requires notification when a resident’s email address or phone number has been accessed by an unauthorised party. Suno is headquartered in Massachusetts.

Deezer assesses its options

Deezer said training data for generative AI should be obtained with permission and compensation. “Any infringement should be sanctioned,” the company said, adding that it was assessing the situation and considering available options. YouTube Music and Genius did not respond to requests for comment, according to the report.

The disclosure arrives as Suno faces a separate lawsuit from Jamendo Music, filed in Massachusetts on 29 June. Jamendo alleges Suno trained on a 55,600-track dataset licensed only for non-commercial academic use, and is seeking at least €17.8 million in damages. Suno declined to comment on those claims.

Suno, meanwhile, says its models are trained on “publicly available music files and related metadata accessible on third-party websites on the open Internet”. It insists its purpose is original creation rather than imitation. Whether courts agree that the route from public webpage to commercial AI model is lawful remains one of the music industry’s biggest unanswered questions.

Why it matters

For people using AI music tools, the report is a reminder that “publicly available” material can still sit at the centre of unresolved copyright and licensing disputes. It also raises uncomfortable questions about breach disclosure when contact details and payment-related information are involved. For the music industry, the alleged source-code evidence could sharpen the argument over whether AI firms have permission to use internet-hosted recordings for training.