Leaked Suno code suggests YouTube scraping
A November breach exposed source code allegedly showing Suno pulled audio from YouTube Music, Deezer, and Genius, and the company never notified customers.
A supply-chain breach at AI music generator Suno, which occurred in November 2025 and only came to light this week, has exposed source code that reportedly reveals the company scraped audio from YouTube Music, Deezer, Genius, stock-music libraries, and podcast RSS feeds to train its models. A hacker used stolen employee credentials to access the code, according to the reporting.
The same breach exposed customer emails, phone numbers, and partial credit card numbers stored via Stripe. Suno has characterized the incident as “a limited security incident that was quickly contained,” and did not notify affected customers when it happened.
Suno had previously said only that it trained on “publicly available music files” from the internet, without specifying sources. Scraping YouTube’s catalog would put it in violation of both the Digital Millennium Copyright Act and YouTube’s own terms of service, and Suno already faces active copyright litigation from major record labels over its training practices. Competitor Udio faces similar accusations over YouTube scraping.
For any operator relying on a generative AI vendor’s public claims about training data provenance, this is a reminder that those claims are effectively unverifiable until something forces disclosure, whether a lawsuit’s discovery process or, as here, a breach the vendor didn’t plan to talk about. If your compliance or legal team has signed off on a vendor’s training-data representations, it is worth asking what happens to that sign-off when the underlying claim turns out to be wrong.