AI music generator Suno suffered a security breach that exposed source code revealing how the company scraped audio from YouTube Music, Deezer, and other platforms for training data.

A hacker used a supply chain attack in November 2025 to access employee credentials, then obtained source code showing Suno's data collection methods. The breach revealed scraping from YouTube Music, Deezer, Genius, stock music libraries, and podcast RSS feeds spanning decades of audio content.

Suno has previously acknowledged training on "publicly available music files" from the open internet, claiming fair use protections under copyright law. The company faces ongoing lawsuits from major record labels challenging this position.

The breach also exposed customer data including email addresses, phone numbers, and partial credit card information stored in Stripe. Suno did not notify customers about the November incident.

Record labels argue Suno's scraping violates the Digital Millennium Copyright Act by circumventing YouTube's anti-scraping protections. The practice also breaches YouTube's terms of service.

Competitor Udio faces similar allegations of YouTube scraping in lawsuits from Sony Music and other labels. Google, YouTube's parent company, confronts separate copyright infringement claims from major book publishers over AI training practices.

Suno described the incident as a "limited security incident that was quickly contained" but provided no timeline for customer notification. The company raised $125 million in Series B funding earlier this year despite the mounting legal challenges.

The hack highlights broader tensions over AI companies' data collection practices and the boundaries of fair use in machine learning training. Music industry lawsuits against generative AI firms are expected to set important precedents for copyright law in the AI era.