AI Music Generation Platform Suno was exposed to hacking, which not only led to user data security issues, but also gave renewed attention to its training data sources. Foreign media reported that the attackers allegedly obtained employee vouchers through supply chain attacks, then entered the company ' s internal system and had access to relevant source codes.

The attackers claimed access to the internal system.

The report cites hackers as saying that they first obtained a sign-in certificate from an employee through a supply chain attack before further access to Suno ' s source code and some internal data. The hackers also stated that the content indicated that Suno could take audio data from several online platforms for long periods of time to train its AI Music Generation Model.

Data sources named include YouTube Music, Deezer, Genius, the Music Bank, and podcasts with RSS subscriptions. If this is true, it means that the capture covers not only the music platform but also sources of content such as lyrics and podcasts.

The training data dispute is magnified.

Suno has previously acknowledged that its model training uses “openly available music documents” on the Internet. The company argued at the time that such training could be included in the “reasonable use” of United States copyright law.

However, several large record companies in Suno are being prosecuted for different views. In their view, if the company deliberately bypasses the technical protection measures set up by YouTube to prevent capture, it may touch on the restrictions of the Digital Millennium Copyright Act and also violate the service provisions of YouTube.

A similar controversy does not appear only on Suno. Udio, its competitor, was also referred to as using the YouTube data training model. At the same time, Google, the YouTube parent company, faces copyright abuse allegations from publishers, and the controversy also focuses on the way AI training data is obtained and used.

Partial client information

It was also reported that hackers had access to customer data, including mailboxes, telephone numbers and some bank card information in the Stripe system. Available information indicates that the disclosed data are not complete payment card information, but that sensitive personal information is already involved.

Suno did not notify his client about the incident in November 2025. The company described it as a “limited and quickly controlled” security incident.

The incident put Suno under two types of pressure at the same time: whether user data protection was in place and whether AI training data were being obtained in a manner that was consistent. Both issues have become an ongoing concern for the revenue-producing AI company.