Radio News Now
Commentary
by Lee Michaels
Suno has built its business by asking people to trust the platform with their ideas, their music, their personal information—and, in many cases, their money.
Now we are learning that information tied to approximately 55.3 million Suno accounts was reportedly caught up in a data breach.
According to Have I Been Pwned data cited by multiple news organizations, the exposed records included email addresses and, in some cases, names, phone numbers, physical addresses, purchase histories and partial payment-card information. Suno has characterized the November 2025 incident as limited and said no sensitive personal information was compromised.
That leaves us with a basic question:
How can a breach affect more than 55 million accounts and still be described to the public as limited?
This is where Radio News Now asks the questions that cannot be answered by repeating a company statement.
Why Weren’t 55 Million Users Told?
Reports indicate Suno discovered the incident in November 2025, investigated it, and decided that individual notification was not required under applicable privacy laws. The public did not learn the full scale until months later.
Perhaps the company’s lawyers concluded that notification was not legally required.
But that is not the only standard that matters.
What about the responsibility Suno had to its users?
There is a major difference between asking:
“What is the minimum the law requires us to disclose?”
and asking:
“What would we want to know if this were our information?”
If a company discovers that unauthorized people accessed information connected to millions of its customers, should those customers have to learn about it from a cybersecurity website or a news report?
I don’t think so.
Users should not need a law degree, a data-breach monitoring subscription, or a lucky Google search to discover that their information may have been compromised.
What Was Actually Exposed?
This is another area where the public deserves a clearer explanation.
Suno has said that no sensitive personal information was compromised and that payment processing was handled securely by Stripe. But reporting about the stolen data has included customer email addresses, phone numbers and partial payment-card details. More recent accounts have also cited names, physical addresses and purchase information.
So which description tells the complete story?
Were 55.3 million email addresses exposed, while only a smaller number of records contained additional information?
Did the type of information vary depending on how a person registered or paid?
Were account passwords involved?
Were login tokens, device information or other authentication data accessed?
Could the exposed records be used to build highly convincing phishing messages aimed specifically at Suno customers?
Those questions matter because criminals rarely need a complete credit-card number to cause trouble.
A name, email address, phone number, physical address, and purchase history can be combined to make a fraudulent message appear legitimate.
The danger is not just direct financial theft.
It is impersonation.
It is phishing.
It is account takeover.
It is someone sending a message that looks enough like Suno to fool a user into handing over the rest of the information.
What About the Music?
Here is the question that every Suno creator should be asking:
Were any songs, lyrics, prompts, voice recordings, uploaded audio files or unpublished creative ideas accessed?
Suno is not merely a social network.
People use the platform to turn text descriptions, melodies, humming, and uploaded audio into complete recordings. Suno itself promotes the ability to create songs from ideas, lyrics, and audio input.
Some users may be creating music for fun.
Others may be developing commercially valuable songs, advertising concepts, jingles, production ideas or works they have not released publicly.
To date, the clearest reporting has focused on customer information and stolen internal source code. I have not seen reliable confirmation that users’ creative files were exposed.
But “we have not seen confirmation” is not the same as “it did not happen.”
Suno should answer this directly:
- Were user-generated songs accessed?
- Were original prompts or lyrics exposed?
- Were uploaded audio recordings involved?
- Were unpublished projects copied?
- Were any voice samples or creator assets taken?
- Has an independent cybersecurity firm verified the answer?
Creators should not be left to guess.
What Did Suno Know and When Did It Know It?
Suno says it quickly contained the incident and that it primarily involved outdated source code.
That statement raises additional questions.
If the company concluded in November 2025 that the breach was limited, what information did that conclusion rely upon?
Did Suno know at the time how many user records were involved?
Did it know customer contact information had been accessed?
Was the company aware that data connected to tens of millions of accounts might later surface outside its systems?
Did the investigation include an independent forensic review, or was the assessment conducted internally?
And perhaps most importantly:
Would Suno have informed users if outside researchers and journalists had not uncovered the scale of the breach?
That is not an accusation.
It is a fair question.
What Suno Should Do Now
This is not the time for carefully polished corporate language.
Suno should provide its users with a plain-English incident report explaining exactly what happened, what information was accessed, and what the company has done since November 2025.
Notify every potentially affected user
Even if Suno believes the law did not require individual notification, the company should notify users now.
Fifty-five million accounts is not a footnote.
Identify every category of exposed information
Do not hide behind vague phrases such as “customer data” or “limited information.”
Tell users whether the breach involved:
- names;
- email addresses;
- phone numbers;
- physical addresses;
- payment-related details;
- purchase histories;
- account identifiers;
- passwords or authentication information;
- songs, prompts, lyrics or uploaded audio.
Require precautionary password resets
There has been no reliable public confirmation that passwords were stolen. However, if there is any uncertainty, Suno should invalidate active sessions and require password changes.
Users should also change the same password anywhere else they reused it.
Strengthen account security
Suno should provide or expand multifactor authentication, active-device review, login alerts, and the ability to terminate unfamiliar sessions.
Provide monitoring where warranted
If records included addresses, purchase histories or payment-related information, Suno should consider providing identity-protection or credit-monitoring assistance to affected users.
That is not an admission of liability.
It is responsible customer care.
Commission an independent security review
Users should not be asked to accept only the company’s internal assessment.
A respected outside cybersecurity firm should examine the breach and publish a meaningful summary of its findings.
Explain its data-retention policy
Why was each category of customer information being stored?
How long does Suno retain it?
Who can access it?
Can users permanently delete their personal data and creative material?
The safest information is sometimes the information a company no longer keeps.
A Wake-Up Call for Every Online Service
This story is bigger than Suno.
Online platforms across music, radio, podcasting, video, artificial intelligence and independent media are collecting enormous amounts of user information.
They may store:
- unreleased music;
- scripts and lyrics;
- private interviews;
- voice recordings;
- business plans;
- financial records;
- audience databases;
- photographs;
- personal communications;
- creative ideas that have never been made public.
Many of these companies are racing to add users, release new features, and attract investment.
But are they investing equally in cybersecurity?
Are they collecting more information than they need?
Are they keeping it longer than necessary?
Do they have a response plan that begins with protecting users—or one that begins with protecting the company’s reputation?
Security cannot be something a business addresses after growth.
Privacy cannot be treated as a feature that gets added in the next software update.
When a platform accepts someone’s personal information or creative work, it also accepts the responsibility to protect it.
And when that protection fails, transparency should come before public relations.
What Suno Users Should Do
While major questions remain, Suno users should take basic precautions:
- Change the password used for Suno.
- Change it anywhere else the same password was reused.
- Enable multifactor authentication where available.
- Be suspicious of unexpected Suno-related emails and text messages.
- Avoid clicking account-security links sent through unsolicited messages.
- Review payment accounts for unfamiliar activity.
- Keep backup copies of important music and creative projects outside the platform.
- Watch for messages referencing real Suno purchases or account details, because stolen information can make scams more convincing.
Users should also remember that criminals often exploit the publicity surrounding a breach.
A fake message offering to “secure your Suno account” could be the very mechanism used to steal additional information.
The Bigger Question
AI companies are asking people to trust them with an extraordinary amount of information.
Our music.
Our voices.
Our words.
Our images.
Our ideas.
Our identities.
Our payment information.
But are these companies building their security systems as quickly as they are building their artificial-intelligence systems?
Or is the rush to grow moving faster than the responsibility to protect the people fueling that growth?
Innovation without accountability is not progress.
It is risk dressed up as technology.
The RNN Bottom Line
Suno may argue that it met its legal obligations.
That does not end the conversation.
More than 55 million accounts were reportedly affected.
Users were not directly informed when the incident occurred.
The descriptions of what was exposed remain difficult to reconcile.
And creators still need a clear answer about whether any music, lyrics, prompts, uploaded audio, or unpublished work was accessed.
Suno owes its users more than a narrow legal explanation.
It owes them transparency.
It owes them specific answers.
It owes them stronger protection.
And it owes them an explanation of why they had to hear about a breach of this scale months after the company discovered it.
The Big Bad Dawg question is simple:
When a company asks millions of people to trust it with their private information and creative work, does that company believe its responsibility ends with the minimum required by law—or does it extend to doing what is right?
Suno needs to answer.
And every online service holding the personal information and creative work of its users should be listening. 🐶⚠️
Questions Suno Still Needs to Answer
- When did Suno first determine that user information had been accessed?
- Did Suno know in November 2025 that the incident potentially involved more than 55 million accounts?
- Exactly what data was exposed?
- How many records contained names, phone numbers, addresses, purchase histories or payment-related information?
- Were passwords, authentication tokens, or active sessions compromised?
- Were any songs, prompts, lyrics, voice recordings or uploaded audio files accessed?
- Why were users not directly notified?
- Did an independent cybersecurity firm investigate the breach?
- Will Suno provide identity or credit monitoring to affected users?
- What security and data-retention changes has Suno implemented?
- Will Suno publish a complete incident report?
- How will users know this cannot happen again?
