Industry

Hacked Data Shows Suno Scraped Millions of Songs From YouTube and Deezer

Leaked files from a hack reveal that AI music generator Suno scraped millions of songs from YouTube Music, Deezer, and Genius to train its models. The data includes source code and scraping instructions, supporting allegations that Suno bypassed copyright protections. The company faces lawsuits from the RIAA over its use of copyrighted material.

Neura News

Neura News

Neura Market Editorial

July 15, 20263 min read

Originally reported by theverge.com

Hacked Data Shows Suno Scraped Millions of Songs From YouTube and Deezer

Suno's Training Data Exposed in Hack

A hacking incident has revealed that the AI music generator Suno trained its models by scraping millions of songs and lyrics from online audio platforms. The data, obtained by 404 Media, shows that Suno pulled content from YouTube Music, Deezer, and Genius, among other sources.

The leaked materials offer a rare look into what Suno has been collecting from the internet. The company has not disclosed the contents of its training datasets or how it acquired them. This secrecy has been a point of contention in ongoing legal battles.

Legal Challenges Over Copyright

Suno is currently facing several lawsuits that accuse it of using copyrighted material to train its AI models. In a high-profile case filed by the Recording Industry Association of America (RIAA), Suno has admitted to using copyrighted works. The company argues that training on publicly available music files from the open internet is protected under fair use doctrine.

An amendment filed by the RIAA last year goes further. It alleges that Suno intentionally circumvented YouTube's copyright protections by stream ripping tracks from the platform. The leaked data appears to support these claims.

What the Leaked Data Shows

The hacker, who goes by the name "ellie.191," shared materials with 404 Media that include Suno source code from 2023 and 2024. The code contains instructions for scraping audio files from YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and the International Music Score Library Project (IMSLP).

Other leaked code suggests that Suno used a third-party company called Bright Data to scrape music from YouTube. The company also appeared to search for a cappella versions of songs on the platform to obtain vocal-only audio.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

One file related to YouTube Music notes that Suno had consumed 2,013,545 YouTube Music clips at the time it was last updated. Another file indicates that Suno's datasets included hundreds of thousands of hours of YouTube Music, thousands of hours of Deezer, Genius, IMSLP, Jamendo, and Pond5, and hundreds of hours of Freesound and MuseScore lyrics. Additional code shows that Suno sought to download roughly one million hours of podcasts using an online tool called PodcastIndex.

Suno's Response

An unnamed Suno spokesperson told 404 Media that the company's AI models have been trained on publicly available music files and related metadata from third-party websites on the open internet. The spokesperson reiterated that this practice is consistent with what Suno has stated in public filings and disclosures.

Customer Data Breach

The hacker also accessed Suno customer information, including email addresses, phone numbers, and Stripe payment details. Some customers contacted by 404 Media confirmed they had signed up for the service and said Suno never notified them about the security breach.

In a statement to 404 Media, a Suno spokesperson said the company became aware of a security incident in November 2025 and quickly contained the situation. The spokesperson said Suno immediately conducted an investigation and verified that the incident primarily involved outdated source code no longer in use. The company also stated that no sensitive personal information was compromised and that Suno does not have access to customers' full credit card numbers in Stripe.

Based on the limited nature of the customer information believed to be involved, Suno determined that individual notifications were not warranted under applicable privacy laws.

Related on Neura Market

More from Neura News