Industry

Leaked Data Reveals Suno's Widespread Music Scraping From YouTube, Deezer, and Genius

A security breach exposes Suno's training pipeline, sourcing millions of tracks from platforms it now faces lawsuits over.

Last verified:

A security breach at Suno AI has exposed the company’s training infrastructure, revealing that the AI music generator systematically scraped millions of songs and metadata from multiple platforms including YouTube Music, Deezer, and Genius. According to The Verge AI and 404 Media, a hacker operating under the alias “ellie.191” obtained Suno source code from 2023 and 2024 alongside detailed scraping instructions, providing concrete evidence for allegations the company has faced in ongoing copyright litigation.

Scale of Data Collection

The leaked materials document Suno’s extraction targets with granular precision. According to 404 Media’s reporting, Suno had ingested at least 2,013,545 YouTube Music clips as of the data’s last update. Beyond YouTube Music, the datasets included hundreds of thousands of hours from YouTube broadly, thousands of hours each from Deezer and Genius, and hundreds of hours from Freesound and MuseScore. The leaked code also revealed that Suno sought to download approximately 1 million hours of podcast audio via PodcastIndex, an aggregation service.

The scraping operation was not incidental—documentation shows Suno employed Bright Data, a third-party scraping service, to extract tracks from YouTube. Notably, the code suggests Suno specifically searched for a cappella versions of songs, targeting vocal-only audio to isolate training material that would be harder to attribute to original recordings.

Suno’s training practices directly contradict its public stance on data sourcing. The company has consistently maintained opacity around its datasets, stating only that it trains on “publicly available music files” accessible on “the open Internet.” Yet in response to lawsuits filed by the Recording Industry Association of America (RIAA), Suno acknowledged that it deliberately uses copyrighted materials, asserting this practice qualifies as fair use under US copyright law.

The RIAA’s amended complaint, however, alleges that Suno unlawfully circumvented YouTube’s copyright protections through intentional “stream ripping”—downloading and converting streaming content into usable training data. The leaked code substantiates this claim, confirming the systematic extraction methodology the RIAA described.

Security Incident and Customer Exposure

The breach also compromised customer data. According to 404 Media, the hacker accessed email addresses, phone numbers, and Stripe payment information belonging to Suno users. Several affected customers confirmed they had never received notification of a security incident, despite Suno’s later disclosure that it became aware of unauthorized access in November 2025.

Suno stated in a response to 404 Media that the compromised materials consisted of “outdated source code” and that the company “immediately conducted an investigation” upon discovery. However, the specificity and currency of the leaked scraping instructions—spanning 2023 to 2024—suggests the compromised data reflects active or very recent training practices.

Why This Matters

The leaked data materially strengthens the RIAA’s legal position while forcing Suno to defend practices it previously obscured. For the broader AI industry, the incident illustrates the gap between public claims about training data sourcing and the actual infrastructure underlying major generative models. Courts evaluating fair-use arguments in AI training cases will now have concrete evidence of deliberate, large-scale extraction from copyrighted sources—raising the bar significantly higher than the company’s “publicly available” framing suggested.

For Suno users, the breach highlights the security and privacy risks of operating AI services that rely on scraped, rights-contested training data. And for music platforms like YouTube and Deezer, the exposure may accelerate legal countermeasures and technical protections against automated content harvesting.

Frequently Asked Questions

How many songs did Suno scrape from YouTube Music?

According to leaked data reported by 404 Media, Suno had consumed at least 2,013,545 YouTube Music clips as of the data's last update in 2023–2024.

Did Suno notify users about the security breach?

No. Customers contacted by 404 Media said Suno never notified them of the breach, though the company stated it became aware of the incident in November 2025 and contained it quickly.

Is Suno's training on copyrighted music legal?

Suno argues it falls under fair use doctrine, but the Recording Industry Association of America (RIAA) disputes this claim in ongoing lawsuits alleging both copyright infringement and unlawful circumvention of YouTube's protections.

What other platforms did Suno scrape from?

Leaked code shows Suno targeted Deezer, Genius, Pond5, Jamendo, Freesound, the International Music Score Library Project (IMSLP), MuseScore, and PodcastIndex.

#ai-music #training-data #copyright #security-breach #suno