A security breach at AI music generator Suno has exposed details of its training data, suggesting the company scraped millions of songs and lyrics from online platforms. The revelation comes from a hacker who infiltrated Suno's systems and shared the information with 404 Media. The leaked source code reportedly details how Suno collected data from services such as YouTube Music, Deezer, and Genius between 2023 and 2024.

One file within the leaked code reportedly lists over two million music clips scraped from YouTube Music. Other data points suggest tens of thousands of hours of audio were taken from Deezer and Genius. The code also indicates Suno sought out acapella versions of songs on YouTube to aid in vocal generation, and that it used a proxy firm called Bright Data to bypass YouTube's defenses. In addition to music platforms, the datasets also appear to include audio from stock music libraries and podcasts.

Suno has confirmed that a security incident occurred in November 2025, involving outdated source code that is no longer in use. A spokesperson stated that the incident was contained quickly and that no sensitive personal information was compromised. The company also maintains it does not have access to customers' full credit card numbers stored by payment processor Stripe. Suno stated that individual breach notifications were not required under applicable privacy laws.

The leaked information may significantly impact ongoing legal battles against Suno. Major record labels, including Universal Music Group and Sony Music Entertainment, have filed copyright infringement lawsuits against the company. These lawsuits accuse Suno of unlawfully using copyrighted sound recordings to train its generative AI models without permission or compensation. The Recording Industry Association of America (RIAA), which is coordinating litigation against Suno, has alleged that the company copied music through "stream ripping" from YouTube and circumvented copy protections.

Suno has previously acknowledged in court filings that its training data includes "essentially all music files of reasonable quality that are accessible on the open internet." The company argues that its use of copyrighted works for training falls under the legal doctrine of "fair use." Suno also states that its models are trained on publicly available music files and related metadata, and that it does not create login credentials to access paywalled content. The company asserts that its models are designed for "original creation" and do not use artist names as training metadata to discourage imitation.

However, the details revealed by the hacked code could provide concrete evidence for the plaintiffs in these copyright cases. In May, Universal Music Group and Sony Music asked a court to expand the number of alleged infringed works from 560 to over 61,000, potentially increasing statutory damages from $84 million to over $9 billion. A ruling on this expansion is pending. Warner Music Group, which was a co-plaintiff in an earlier lawsuit, settled with Suno in November 2025 and entered into a licensing partnership.

The music industry has been actively proposing systems for labeling AI-generated music, with a coalition of organizations including the RIAA and IFPI advocating for such measures. This push for transparency and labeling comes amid broader concerns in the creative industries about the impact of AI on artists and intellectual property rights.