Tech

Suno AI breach exposes scraping of millions of tracks in RIAA lawsuit context

Files obtained by 404 Media confirm Suno trained models on data from YouTube Music, Deezer, and Genius, bolstering allegations of unlawful circumvention of copyright protections.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: The Verge · original
Suno snatched millions of songs from YouTube, Genius, and Deezer
Leaked source code reveals AI music generator used third-party firm to extract content from protected platforms

Hacked data obtained by 404 Media and attributed to a hacker known as “ellie.191” reveals that AI music generator Suno trained its models by scraping millions of audio tracks and lyrics from major online platforms. The leaked files indicate the company accessed content from YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and the International Music Score Library Project. This disclosure provides a rare insight into Suno’s data acquisition methods, which the firm has previously kept confidential.

The source code and scraping instructions reportedly confirm that Suno utilised third-party firm Bright Data to extract content. One file notes that Suno had consumed 2,013,545 YouTube Music clips at the time of the last update. Additional code suggests the company sought to download approximately one million hours of podcasts via PodcastIndex and specifically searched for a cappella versions of songs on YouTube to source vocal-only audio.

The disclosure supports allegations in a lawsuit filed by the Recording Industry Association of America (RIAA) that Suno unlawfully circumvented copyright protections. While Suno has argued in public filings that training on publicly available music files is permitted under fair use doctrine, the RIAA contends that the method of accessing this data, including “stream ripping” tracks from YouTube, was unlawful. The leaked materials reportedly back up these specific claims regarding circumvention.

Suno confirmed it became aware of the security incident in November 2025, stating that the breach primarily involved outdated source code no longer in use. A spokesperson for the company told 404 Media that no sensitive personal information was compromised, noting that Suno does not hold customers’ full credit card numbers in Stripe. The firm determined that individual notifications were not warranted under applicable privacy laws due to the limited nature of the customer information involved.

Despite these assurances, customer data accessed by the hacker included email addresses, phone numbers, and Stripe payment details. Some customers contacted by 404 Media confirmed they had signed up for the service but were never notified of the breach. The hacker reportedly gained access by deploying a worm against a Suno employee to obtain credentials for GitHub and cloud services.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon