Houston News Buzz

collapse
Home / Daily News Analysis / Suno snatched millions of songs from YouTube, Genius, and Deezer

Suno snatched millions of songs from YouTube, Genius, and Deezer

Jul 21, 2026  Twila Rosenbaum 8 views
Suno snatched millions of songs from YouTube, Genius, and Deezer

A major data breach at Suno, the AI music generation startup, has laid bare the scale of its training data collection, revealing that the company scraped millions of songs from platforms like YouTube Music, Deezer, and Genius. The leaked files, obtained by hackers and reported by 404 Media, provide the clearest evidence yet of how Suno built its AI models, which can generate music from text prompts. The incident intensifies the ongoing legal battle over whether using copyrighted works for AI training constitutes fair use or massive infringement.

The Leaked Data and Its Implications

Hackers, using the alias “ellie.191,” shared source code from 2023 and 2024 with 404 Media, along with detailed scraping instructions. These documents show that Suno systematically downloaded audio files from YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and the International Music Score Library Project (IMSLP). The code also indicated that Suno employed a third-party company, Bright Data, to scrape YouTube, and that it specifically searched for a cappella versions of songs to isolate vocal tracks. One file recorded that Suno had consumed over 2 million YouTube Music clips. Other datasets included hundreds of thousands of hours from Deezer, thousands of hours from Genius, IMSLP, Jamendo, and Pond5, and hundreds of hours from Freesound and MuseScore lyrics. The company also attempted to download about one million hours of podcasts via PodcastIndex.

This unprecedented disclosure gives the public a rare, detailed view of the contents of Suno’s training sets. The company has consistently refused to reveal what it has ingested, citing trade secrets. The leaked materials now serve as a roadmap for the Recording Industry Association of America (RIAA) and other plaintiffs in their ongoing lawsuits against Suno. In a notable case, the RIAA has alleged that Suno “stream ripped” tracks from YouTube by circumventing its copyright protections. The leaked code appears to confirm that practice, as it includes instructions for downloading audio from YouTube despite the platform’s technical safeguards.

The Legal Landscape and Fair Use Arguments

Suno has openly admitted to training on copyrighted materials, arguing that doing so falls under the fair use doctrine. The company claims its models transform the original works into something new and that the data is scraped from publicly available files on the open internet. However, critics and rights holders counter that the scale and purpose of Suno’s scraping amount to direct competition with the music industry, especially since Suno’s paid subscriptions allow users to generate songs that mimic the style of existing artists. The leaked data complicates Suno’s fair use defense, as it shows the company targeted specific platforms and even sought vocal-only versions of songs. This suggests a deliberate effort to collect high-quality, rights-protected content.

Other AI companies have faced similar scrutiny. Stability AI and OpenAI are also being sued over their training data practices. The legal outcome of these cases could set a precedent for the entire generative AI industry, determining whether training on copyrighted works without permission is permissible. The Suno breach adds another layer to this debate, as it reveals not only the content scraped but also the methods used to obtain it. If courts rule that circumventing platform protections like YouTube’s copy-protection measures is unlawful, Suno could face enhanced damages.

Security Breach and Customer Impact

Beyond the training data revelations, the hacking incident also compromised customer information. The hacker accessed email addresses, phone numbers, and Stripe payment details of Suno subscribers. Several affected customers told 404 Media they never received a breach notification from Suno. The company acknowledged the incident in a statement, saying it became aware of the intrusion in November 2025 and contained the situation quickly. Suno claimed that the stolen data consisted primarily of outdated source code and that no sensitive personal information was compromised. However, the company also stated that it does not have access to full credit card numbers in Stripe, suggesting that partial payment data may still be at risk. Privacy experts have criticized Suno for not notifying customers, as many states require disclosure when financial information is involved.

The breach underscores the vulnerability of AI startups that rapidly accumulate large datasets and maintain expansive digital infrastructure. Suno, like many peers, had prioritized speed of development over security, making it an attractive target for hackers. The leaked code also reveals the internal architecture of Suno’s data pipeline, including how it organized and labeled millions of audio files. This information could be valuable to competitors, but also to regulators investigating data provenance in AI training.

The Broader Context of AI Music Generation

Suno’s success in generating eerily realistic music has sparked both excitement and alarm. Musicians and labels worry that AI could devalue human creativity and flood the market with derivative works. Some artists have spoken out against AI music, with SZA recently calling such technology “disgusting.” Meanwhile, tech enthusiasts argue that AI empowers new forms of expression. Suno itself has touted its tool as a way for anyone to make music, regardless of training. But the means by which it obtained its capabilities have now been laid bare, and the public reaction has been mixed. The leaked data has galvanized calls for transparency in AI training, with many demanding that companies disclose their sources and obtain proper licenses.

The music industry is already adapting. Record labels are exploring licensing deals with AI companies, while streaming platforms are developing detection tools for AI-generated content. TikTok, for instance, is testing an AI likeness detection tool. However, the Suno breach shows that much of the early training was done without any agreements in place. The company’s argument that scraping publicly available data is fair use may be tested in court soon. If the judges side with the RIAA, Suno could be forced to delete its models or pay substantial damages. Conversely, a win for Suno would legitimize the practice and open the door for even more aggressive data collection by AI firms.

As the legal battles unfold, the tech community is also grappling with ethical questions. Is it fair to use an artist’s entire catalog without permission to train a competing product? Can a model be considered transformative if it can reproduce the style of copyrighted songs? The Suno case is a bellwether for these issues. The company has remained defiant, insisting that its training practices are lawful and that the hacking incident is an invasion of privacy. Yet the leaked files have forced an uncomfortable conversation about the foundations of generative AI. The industry may have to reckon with the fact that many of its most impressive tools were built on a massive, unlicensed collection of human creativity.

The hack also raises questions about data security in the AI sector. Startups often operate with small teams and limited budgets for cybersecurity, making them prime targets. Suno’s experience is a cautionary tale for other companies: the same datasets that power your product can also be your biggest liability. As more details emerge from the breach, it will likely inform how regulators think about data governance in AI. Lawmakers in the US and EU are already drafting frameworks that require companies to document their training data sources. If Suno had maintained such documentation voluntarily, it might have avoided some of the legal and reputational damage. Instead, the breach has done the documenting for them.

The future of AI music now hangs in the balance. If Suno prevails in court, the floodgates could open for AI music generation without licensing costs. If it loses, it could set back the industry by years. Either way, the leaked files have permanently changed the conversation around AI training data. They have shown that companies will go to great lengths to obtain the data they need, and that nothing remains hidden forever. The music industry, regulators, and the public are now watching closely to see how Suno responds—and what the next hack might reveal about the true cost of artificial intelligence.


Source:The Verge News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy