HackMyIP
← Back to News
2026-07-22 SecurityWeek

Suno and Paidwork Breaches Expose 78M Records – Check Your Data

Data BreachAI SecurityPrivacy

Hackers have stolen tens of millions of user records from AI music generation platform Suno and gig-work marketplace Paidwork, according to breach notification service Have I Been Pwned (HIBP). The Suno intrusion occurred in November 2025 and surfaced publicly when 404 Media reported that attackers had exfiltrated source code alongside user data. The leaked source code revealed that Suno had been scraping copyrighted music and podcast content from platforms including Deezer, YouTube, and Genius—raising both copyright and AI training data concerns.

HIBP's analysis of the Suno dataset identified 55.3 million unique email addresses, along with phone numbers and tens of thousands of Stripe payment records containing names, physical addresses, purchase amounts, and partial card data (card type, expiration date, and last four digits). For Paidwork, a threat actor leaked an 11 GB database allegedly stolen in March 2026, claiming it contained records on roughly 22 million users. HIBP confirmed 23.3 million unique email addresses in the trove, plus names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, financial transaction histories, and profile information—a far more sensitive dataset than the Suno leak. Users can immediately verify their exposure using an email breach checker and should rotate any reused credentials with a strong password checker to evaluate strength.

The combined exposure of nearly 78 million records significantly elevates risks of credential stuffing, financial fraud, and targeted phishing campaigns. The inclusion of bank account numbers and full transaction histories in the Paidwork dataset is particularly severe, potentially enabling account takeover and identity theft. Paidwork issued a statement to SecurityWeek acknowledging the HIBP report but claimed no confirmed evidence of a system compromise, saying the matter has been escalated to its security team for investigation. Suno has not publicly responded at the time of writing.

Both incidents underscore the expanding attack surface of AI-driven and gig-economy platforms, where large-scale data collection meets often-inadequate security controls. Organizations handling payment and personal data at this scale should prioritize encryption of sensitive fields, robust authentication mechanisms, and continuous monitoring for anomalous data exfiltration. Individuals affected by either breach should monitor financial accounts, enable multi-factor authentication on linked services, and run a full privacy checkup to identify other exposed endpoints.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →