Musicbusinessworldwide.com
AI music platform Suno is facing a proposed class action lawsuit after a reported data breach allegedly exposed the personal information of more than 55 million users, adding another legal challenge for the fast-growing company.
The lawsuit was filed in the U.S. District Court for the District of Massachusetts, where Suno is headquartered. Florida resident and Suno customer Alec Pilavian is the named plaintiff and is seeking to represent all U.S. users whose information was allegedly compromised.
According to the complaint, unauthorized access to Suno’s systems occurred around Nov. 2025, resulting in the theft of user information that reportedly included names, mailing addresses, email addresses, phone numbers, purchase histories and partial payment card details. The filing claims affected users were not informed of the incident for several months and instead learned of the breach after it became publicly known in July 2026.
The reported breach drew widespread attention after breach notification service Have I Been Pwned added the dataset to its database, identifying approximately 55.3 million unique email addresses as potentially affected.
In response, Suno said it is reviewing the lawsuit while emphasizing that protecting user data remains a top priority. The company stated that the Nov. 2025 security incident was quickly contained and that an internal investigation, supported by an independent cybersecurity firm, concluded the breach primarily involved outdated source code and a limited amount of user information.
It was also noted that the platform does not store complete payment card information or collect users’ bank account details.
The lawsuit argues that Suno failed to implement adequate cybersecurity measures and alleges the company delayed notifying customers after discovering the incident. Plaintiffs claim users now face an elevated risk of identity theft, fraud and other privacy-related harms as a result of the exposure of their personal information.
Among its requests, the proposed class action seeks monetary damages, stronger cybersecurity protections and at least ten years of credit monitoring services for affected users.
