Skip to content
Color theme
Back to intake

Incident record

What is reported—and disputed—about the Suno incident

The public record contains materially different descriptions. This intake attributes each position instead of treating disputed claims as settled facts.

01

Reported timeline

Suno says it determined in November 2025 that it had experienced a limited security incident and quickly contained it. The broader claimed dataset became public in July 2026 through reporting and Have I Been Pwned.

02

Reported scale

Have I Been Pwned reports more than 55 million unique email addresses. Phone numbers were present where used for signup, and tens of thousands of Stripe purchase records reportedly appeared in a smaller portion of the corpus.

03

Reported information

Have I Been Pwned lists email addresses, phone numbers, names, physical addresses, purchase details, and partial payment-card fields such as card type, expiration date, and last four digits. It does not report full card numbers, and Suno says it cannot access full card numbers in Stripe.

04

Suno’s position

Suno has said the incident primarily involved outdated source code no longer in use and that no sensitive personal information was compromised. Suno reportedly determined that individual notifications were not warranted. Hall Attorneys will evaluate source records rather than treating either side’s description as conclusive.