AIO APEX

A hack exposed Suno's secret: it scraped YouTube to train its AI music model

TechCrunch
Share:
A hack exposed Suno's secret: it scraped YouTube to train its AI music model

A November 2025 supply chain attack on AI music generator Suno has exposed more than a security incident — it revealed exactly how the company built its model. An unauthorized actor obtained employee credentials, gained access to Suno's source code, and found evidence that the startup had been systematically scraping audio from YouTube Music, Deezer, Genius, stock music libraries, and podcast RSS feeds for years, as first reported by 404 Media and covered by TechCrunch.

What the hack revealed

The attacker accessed Suno's internal systems using a compromised employee credential in a classic supply chain intrusion. Inside the source code, they found the infrastructure Suno uses to pull and process audio at scale — specifically targeting platforms with catalogues large enough to cover a wide range of musical styles, genres, and production techniques. YouTube Music, with its combination of official releases and user-uploaded content, appears to have been the primary source.

This matters because Suno has publicly maintained that it trains on "publicly available music files" under fair use doctrine. The breach documentation suggests the company was actively circumventing YouTube's anti-scraping protections, which is a different claim entirely — and one that directly contradicts Google's terms of service and potentially violates the Digital Millennium Copyright Act.

The copyright battle just got harder to defend

Record labels — including Universal Music Group, Sony Music, and Warner Music Group — are already suing Suno in federal court over copyright infringement. The breach evidence is the kind of internal documentation that lawyers dream about: it shows not just that the model was trained on protected audio, but that the company built specific tooling to extract it from platforms that prohibit scraping.

Competitor Udio is facing similar accusations, and Google itself is dealing with copyright lawsuits from major publishers over its AI training practices. But Suno's case looks harder to defend now that internal tooling confirming the YouTube scrape has surfaced outside the company.

Customer data was also stolen — and no one was told

The breach didn't only expose Suno's training methodology. The attacker also accessed customer data: email addresses, phone numbers, and partial credit card numbers stored via Stripe. Suno characterized the incident as "a limited security incident that was quickly contained" — but did not notify affected customers directly. Under regulations like GDPR and most US state breach notification laws, that omission may itself be a compliance problem depending on the scope and timing.

For users who signed up with a credit card or real phone number, the breach is a concrete privacy concern, not just an abstract corporate dispute. Suno has not publicly disclosed how many accounts were affected.

Why this keeps happening

AI companies face a structural incentive problem: the models that win commercially are trained on the most diverse, high-quality datasets. Licensing that audio at scale from rights holders is expensive and slow. Scraping it is fast and cheap — until a breach, a lawsuit, or both makes the cost structure collapse. Suno is the latest example, but it almost certainly won't be the last.

Originally reported by TechCrunch. Read the original article for additional details.

View original source
Share: