Hacked Suno Code Exposes Training Library: Scraped Roughly 380,000 Hours From YouTube Music and Others
A worm breached Suno, and leaked source code shows the sites it scraped from and for how long. User data also surfaced; the company says it doesn't need to notify users individually.
- A hacker (alias ellie.191) used a worm called Shai-Hulud to compromise Suno employee accounts and handed source code related to training data to 404 Media.
- Code comments list scraping from YouTube Music, Pond5, Deezer, Genius, and others; nine libraries total about 380,000 hours. One file, youtube_music, records over 2.01 million audio segments scraped.
- Scraping used Bright Data proxies to pull from YouTube and specifically searched for a cappella tracks. There was also a plan to download roughly 1 million hours from about 420,000 podcasts; this was the intended scope, not necessarily a record of completed downloads.
- The same breach exposed Suno user emails, phone numbers, and Stripe-related payment info. The hacker told 404 Media it involved several hundred thousand users. TechCrunch reported some card data was also present.
- Suno says the incident was detected in November 2025, had limited impact, mainly involved superseded code, and that it couldn't access full card numbers, so it wasn't legally obligated to notify users individually. Some users told 404 Media they never received any notification.
Suno gets hacked, revealing two things
AI music company Suno was breached. A hacker known as ellie.191 used a worm called Shai-Hulud (literally, "sandworm") to compromise employee login credentials, obtain source code related to training data, and pass it to tech outlet 404 Media.
The most striking part of the leaked code is the scale and sources of the training set: YouTube Music, Deezer, Genius, and Pond5 are all named in comments, adding up to roughly 380,000 hours. There's also a plan to download about 1 million hours of podcasts.
- 113,879 hours · YouTube Music (youtube_music)
- 152,162 hours · Another YouTube library (ytm_tagged, the largest single item)
- 62,117 hours · Pond5 stock library
- 12,287 hours · Deezer, plus Genius lyrics data
- ~1 million hours · Podcast download plan (approx. 420,000 shows)
In the same breach, the hacker also accessed Suno user emails, phone numbers, and payment-related data from Stripe. They told 404 Media it involved "several hundred thousand" users. TechCrunch, in its coverage, noted that partial card numbers were among the accessed material.
Suno's response: the security incident was detected in November 2025, was quickly contained, and had limited impact, so individual notification wasn't required. Some users who spoke to 404 Media, however, said they only learned about the potential exposure from the news.
Shai-Hulud is a supply-chain worm: instead of attacking the company directly, it targets the tools and credentials on developers' machines to steal GitHub, cloud, and other accounts. Hacker ellie.191 told 404 Media they used this worm to compromise a Suno employee. When asked why they targeted Suno, the hacker's response was essentially: they like to hack everything.
Where the data came from, and how much there is
The source code seen by media outlets dates from roughly 2023 to 2024. One set of comments outlines data sources, noting non-music content will be filtered out.
genius_hq, youtube_music, freesound, jamendo, imp (IMSLP), deezer, ytm_tagged
Other datasets like pond5_music and musescore_lyrics are also referenced. Comments included the note "non-music will be filtered out."
How the code went about scraping
So much for how much. Here's how it was done. Music Business Worldwide and other outlets pulled additional specifics from 404 Media's materials.
YouTube: Proxies and a cappella searches
The code shows Suno used Bright Data's proxy service to scrape tracks from YouTube. It also searched for "a cappella" — vocal-only versions — seemingly with the goal of isolating singing voices.
The stream ripping that labels accuse Suno of means recording audio while it plays in real time to save it as a file. The process in the source code is clearly batch-run via scripts, which is different from a model occasionally listening to a few tracks online.
Podcasts: A plan for about 1 million hours
There's another line in the code: using PodcastIndex to identify roughly 420,000 podcasts. The filters appear to require at least 5 episodes per show and episodes of roughly 30 minutes, with the goal of downloading about 1 million hours of audio.
That 1 million hours is described as a download plan. Public reporting doesn't confirm it all was completed or used for training. The nine libraries totaling ~380,000 hours are a separate, clearly annotated figure — don't mix them up.
What the company says about "public data"
Suno has stated in court documents and its California disclosure page that training uses publicly accessible music files online and that it respects paywalls and password protection. Yet Deezer and Pond5, which are named, typically require payment or a subscription. How Suno reconciles "respecting paywalls" with obtaining these sources isn't detailed in available public materials.
How this connects to the litigation
Suno is already in court with major record labels. The leaked source code fills in details about "what" and "how" it scraped.
The first layer is copyright: is copying songs for training fair use under the law? The second is technical protection: did Suno bypass YouTube's download protections? Even if the first is unresolved, the second can stand alone. This leak primarily serves to solidify the "massive downloading from YouTube" claim.
As we have stated in public filings and disclosures, Suno’s AI models have been trained on publicly available music files and related metadata accessible on third-party websites on the open Internet. Suno spokesperson responding to 404 Media (via Music Business Worldwide)
What the company said, and what users knew
One issue is potential copyright infringement in training data. Another is whether user data was compromised and whether users were notified. Both stem from the same intrusion.
Detected a limited incident in November 2025 and contained it quickly. Mainly involved superseded source code. No sensitive personal information was compromised. Suno doesn't have access to full card numbers on Stripe. Therefore, it believes it isn't legally required to notify every user. On training data, it says it's already made public disclosures per California law.
Hacker ellie.191 says they could see emails, phone numbers, and Stripe-related info for several hundred thousand users. TechCrunch reported the material included some card numbers. 404 Media's Jason Koebler wrote on Bluesky that users were never notified. Some customers confirmed to 404 Media they hadn't received any breach notification and found out from the news.
Currently, two facts seem solid. First, Suno judged this a "limited incident" and didn't think individual notification was required. Second, at least some users first heard about it from media in July 2026. Whether full card numbers were exposed, and what specific fields were visible in Stripe, will depend on future statements, regulatory findings, and litigation results.
Suno's California AB 2013 disclosure page still states the training set comprises tens of millions of public music files and related text descriptions, collected since spring 2023, possibly including public domain and copyrighted works, and that it respects paywalls and passwords. What this leak added are specifics missing from previous vague statements: the specific site names, hours per library, use of Bright Data proxies, and the specific search for a cappella tracks.
The hacked data is a rare look at exactly how AI models and tools are built. Jason Koebler / 404 Media, 2026-07-15
Primary source: 404 Media original report (Jason Koebler, 2026-07-15). The latter half of 404's piece is paywalled; the free portion covers dataset hours. Details on the worm, Bright Data, a cappella searches, podcast plans, company statements, users not being notified, and the Jamendo suit were cross-referenced with Music Business Worldwide, Variety, TechCrunch, TechTimes, and the author's Bluesky. Suno's own disclosure page: California AB 2013. The nine library hour counts are summed directly; the ~1 million hours of podcasts refers to the scale of the download plan.
Leaked Suno Code Shows Scraping of ~380K Hours from YouTube Music & Others; User Data Also Exposed
A supply-chain worm breached Suno, revealing not just the sources and scale of its training data, but also user emails, phones, and payment info. Suno says individual notices aren't needed.
↓ One page, complete with an animated diagram
Hacker ellie.191 used a supply-chain worm called Shai-Hulud ("sandworm") to gain access to a Suno employee's account, handing over training-related source code from 2023-2024 to 404 Media. The same intrusion exposed user emails, phone numbers, and Stripe payment-related data.
Suno deemed the impact limited and saw no need for individual notices, but roughly 8 months passed between discovery and public exposure.
Code comments list target libraries and their hour counts. Verified by 404 Media and follow-ups, the nine libraries sum to roughly 382,000 hours.
| Dataset | Hours | Notes |
|---|---|---|
| ytm_tagged | 152,162 | YouTube-related, largest single item |
| youtube_music | 113,879 | Also notes 2.01M+ segments |
| pond5_music | 62,117 | Stock library, owned by Shutterstock |
| imslp | 19,514 | Sheet music site IMSLP |
| genius_hq | 17,615 | Lyrics site; tracks often embedded |
| deezer | 12,287 | Subscription streaming service |
| jamendo | 3,726 | Another plaintiff (see later) |
| freesound | 410 | |
| musescore_lyrics | 103 |
The two YouTube-related items (ytm_tagged + youtube_music) total about 266,000 hours, roughly 70% of the nine-dataset sum. The separate podcast plan targets about 1 million hours; it's detailed in the next section.
Seeing "how much" isn't enough—the code also shows "how." Xiaohu walked through the logic step by step.
Nine datasets totaling roughly 382,000 hours
The ~1 million hour podcast plan is an intended target from ~420,000 shows, not proof everything was downloaded and used.
Suno is already being sued by Universal, Sony, and others. The leaked source code now adds specifics to the "from where" and "how" of the allegations.
The training data is one issue; the handling of user information is another. Both stem from the same intrusion.
Detected in Nov 2025, contained quickly, impact limited; mainly superseded code; doesn't have access to full credit card numbers, so no individual notice required. Training data disclosures made per California law.
Hacker ellie.191 says they saw emails, phones, and Stripe data for hundreds of thousands of users. TechCrunch's report mentions partial card numbers. Users told 404 Media they received no notification and learned from the news.
fully leaked
hours
make up ~70%
- × YouTube Music
- × Deezer
- × Genius
- × Pond5
of user records
No need to notify everyone
