In short: In July 2026 Have I Been Pwned added a breach of the AI music generator Suno to its database: 55.3 million accounts were compromised. The hack itself happened back in November 2025, but users were never told — the company claimed "no sensitive personal information was compromised," even though the dump contained phone numbers, addresses and partial Stripe payment details. Check your email on HIBP and turn on two-factor authentication.
What happened?
On 21 July 2026 Have I Been Pwned (HIBP) added data stolen in a breach of Suno — a popular AI music generation service — to its database. The incident affected 55.3 million unique accounts. The hack itself occurred back in November 2025, but it only became public now, thanks to reporting by the outlet 404 Media rather than any notification from the company itself.
The key problem here is not only the scale but the silence. Suno decided that notifying affected customers individually was not required, and publicly stated that "no sensitive personal information was compromised." This is exactly the scenario where leaked data is used by criminals for months while victims have no idea they are in a database — as we covered in our report on the leak of billions of credentials.
What data was leaked?
Contrary to the company's statement, the dump contained a substantial set of personal data: email addresses, phone numbers, names and physical addresses, along with purchase records. The payment block is especially worrying: tens of thousands of Stripe transaction records included the name, physical address, purchase amount, card type, expiration date and the final four digits of the card number.
Beyond user data, the attackers also exfiltrated part of Suno's source code, revealing details of how the company trains its AI models. For an ordinary user this means one thing: the "email + phone + address + partial card" set is more than enough for targeted phishing and social engineering, even without the full card number in the leak.
Why is this dangerous for your data?
The combination of email, phone and physical address is ready-made material for convincing phishing: a scammer knows you are a customer of a specific service and can write in its name. The last four digits of a card and its expiration date are often used in "confirm your card" schemes, and a phone number opens the door to SMS phishing and attempts to intercept one-time codes. Worst of all, in an eight-month-old breach the data may have circulated on underground forums long before public disclosure.
A breach on the service side is something you cannot prevent: the data was held by Suno, and the company was the one responsible for protecting it. But you can limit the damage. A VPN will not undo a leak, but a no-logs VPN encrypts your traffic on open networks and hides your real IP, keeping logins and sessions from being intercepted when — for example — you rush to change passwords from a café or airport.
How to check yourself and stay protected?
Check your email on Have I Been Pwned. Enter your address on the HIBP website — if it appears in the Suno breach or other databases, you will see it immediately.
Change your password and enable two-factor authentication. If you registered with Suno, change your password there and everywhere you reused it. A password manager helps you keep a unique password on every service, and 2FA stops anyone logging in with a password alone.
Be wary of "notifications" about your card and purchases. Do not click links in emails or texts that claim to confirm a transaction: go to the service directly. A real bank never asks you to "confirm" a card via a link.
Encrypt your connection on other people's networks. On open Wi-Fi a VPN routes your traffic through an encrypted tunnel so logins and sessions cannot be intercepted, and hides your IP. LiMP VPN is a no-logs service for iOS and Android — see the features and plans, with more security news on our blog.
Sources
This report is based on data from Have I Been Pwned and reporting by TechCrunch and Xakep (July 2026), referencing the 404 Media investigation.
