Suno, the generative AI music platform valued at $5.4 billion, just had its homework exposed. A leaked trove of internal source code and logs reveals the company scraped over 2 million clips from YouTube Music, totaling roughly 113,879 hours of audio, as part of its training data pipeline.
The breach also showed significant audio harvesting from Deezer (12,287 hours), Genius (17,615 hours), Pond5 (62,117 hours), and smaller contributions from Jamendo and Freesound, plus about a million hours of podcast RSS feeds.
How the leak happened
The breach traces back to November 2025, when a supply-chain attack compromised an employee credential through the Shai-Hulud npm worm. In English: a piece of malicious code wormed its way into the software tools Suno’s developers rely on, then used stolen login details to access internal systems.
The leaked documents were made public in mid-July 2026 by a hacker going by “ellie.191” and first reported through 404 Media. The exposed files include detailed logs of Suno’s scraping operations, painting a remarkably clear picture of exactly where the company sourced its training data.










