The AI music platform Suno had more than 55 million accounts exposed, according to Have I Been Pwned. The incident itself happened in November 2025 but only became public in July 2026. Exposed data includes email addresses and phone numbers used at registration, plus tens of thousands of Stripe payment records containing names, physical addresses, transaction amounts and partial card data (card type, expiry, last four digits). Suno states full card numbers were not accessible to it. Notably, Suno concluded it was not required to notify affected users individually — so many people have no idea they were caught in this.
After a breach: the part most people skip
A leaked email and phone number don't just sit in one dump — data brokers buy breach data, merge it with public records, and resell it. That's why the spam calls and phishing texts keep coming months later. Deleting your data from the breached company is only the first step; getting it out of the broker network is what actually stops the follow-on damage.