In brief
A hacker using the Shai-Hulud worm breached Suno in 2025 and leaked source code showing the platform scraped over 113,000 hours from YouTube Music, 62,000 from stock library Pond5, and 12,000 from Deezer, among other sources.
The same intrusion reached customer emails, phone numbers, and Stripe payment data for what the hacker describes as hundreds of thousands of users.
Suno's own California compliance disclosure had already acknowledged that its training data may include music "subject to intellectual property protection"
A hacker broke into AI music platform Suno and walked out with source code that documents, in precise detail, exactly where the company's training data came from.The breach was first reported by 404 Media, which reviewed the leaked files. It confirms what the music industry had been saying in courts since 2024.The intruder claims to have used a piece of malware called the Shai-Hulud worm—named after the enormous sandworms in Frank Herbert's Dune. Suno, one of the largest AI music generators online, lets users type a text description and receive a full song in seconds; building that capability required a substantial training dataset—a collection of audio files used to teach the model what different genres and styles sound like.The leaked material consists of scraping instructions and internal logs from 2023 and 2024, offering a rare look at how those pipelines are actually assembled.The dataset breakdown is specific. According to internal file comments reviewed by 404 Media, the training library included 113,879 hours of YouTube Music, 152,162 hours of tagged YouTube tracks, 62,117 hours from stock music library Pond5, 12,287 hours from Deezer, and 17,615 hours in a dataset labeled genius_hq, associated with material collected through Genius. The code also documented plans to download roughly 1 million hours of podcast audio via RSS feeds.










