Suno and Paidwork Data Breaches: Information of Millions of Users Leaked – Veri Sızıntısı

Suno and Paidwork Breaches Affect Millions

AI music generator Suno and gig-work platform Paidwork are at the center of massive data breaches affecting nearly 80 million user records in total. The leaked data includes financial information and personal identification details.

Suno and Paidwork logos in front of a broken padlock icon

What Happened

The security of our personal data in the digital world has once again taken a serious hit. The popular AI music generator Suno and Paidwork, a platform for earning extra income through micro-jobs, have become victims of two major cyberattacks, exposing the personal and financial information of millions of users. Analyses by the data breach notification service Have I Been Pwned (HIBP) reveal the severity of the situation. A total of nearly 80 million unique email addresses have been identified in the data leaked from the two platforms.

The attack on Suno reportedly occurred in November 2025, but the incident came to public light earlier this month when 404 Media reported that hackers had obtained both its source code and user data. The attack on Paidwork is claimed to have taken place in March 2026. Last week, a threat actor leaked an 11 GB database allegedly stolen from Paidwork, said to contain the information of roughly 22 million users.

The Compromised Data

The nature of the data leaked in both breaches poses serious risks to users. The sensitivity of the data goes far beyond a simple email list, creating a foundation for crimes such as fraud, identity theft, and financial scams.

Details of the Suno Breach

According to Have I Been Pwned's analysis, the database leaked from Suno contains 55.3 million unique email addresses. However, the risks are not limited to this. The leaked data also includes:

  • Phone Numbers: These can be used for SMS phishing (SMiShing) and fraudulent phone calls, allowing attackers to target users directly.
  • Stripe Payment Records: Said to belong to tens of thousands of users, these records are a treasure trove for cybercriminals. They include users' names, physical addresses, purchase amounts, and partial payment card information (card type, expiration date, and the last 4 digits of the card number). This information can be used to orchestrate highly convincing and targeted phishing attacks. An attacker could reference a user's past transaction in a fraudulent email to request additional information or payment.
  • Source Code: In addition to user data, it is noteworthy that Suno's source code was also stolen. Examination of the leaked code revealed that Suno was scraping music and podcast content from major platforms like Deezer, YouTube, and Genius. This could expose the company to legal trouble over copyright infringement.

Details of the Paidwork Breach

The data leaked from Paidwork, a platform where freelancers earn money by completing small tasks, is much more sensitive and directly financial. HIBP identified 23.3 million unique email addresses in this breach. Other information in the massive 11 GB database includes:

  • Personal Identifiable Information (PII): Users' full names, physical addresses, and dates of birth. This combination of three pieces of information provides a sufficient basis for identity theft.
  • Password Hashes: Although the users' actual passwords were not leaked, their cryptographic hashes were. This still poses a significant risk. If weak passwords or outdated hashing algorithms were used, these hashes could be cracked to reveal the original passwords. If users reused the same password on other platforms (credential stuffing), their other accounts are also at risk.
  • Financial Information: Most alarmingly, bank account numbers and financial transaction records were leaked. This information can be used for direct fraudulent attempts on users' bank accounts.
  • Contact and Profile Information: Phone numbers and user profile information are also among the leaked data.

How Did the Attack Happen

The source article does not provide any technical details about either attack. Other than the claims that the Suno attack occurred in November 2025 and the Paidwork attack in March 2026, it is not yet known how the attackers infiltrated the systems, what vulnerabilities they exploited, or what the attack vectors were. The companies have not made any official statements on this matter.

Who Is Affected

These data breaches affect a broad user base, including:

  • Suno Users: Artists who create music with AI, content creators, hobbyists, and tens of thousands of people who use the platform's paid features. Their payment information and personal data are at risk.
  • Paidwork Users: Freelancers, students, and digital nomads who earn extra income by completing small tasks online. Considering that this demographic may be more financially vulnerable, the leak of bank account numbers could lead to serious harm.

The leak of email addresses and associated data for a total of 78.6 million users shows what a large portion of the global user base of these two platforms is at risk.

What You Can Do

If you have an account on either the Suno or Paidwork platforms, you need to take immediate action against the possibility that your data has been compromised. Here are the steps you should take:

  • Check Your Accounts: First, visit the Have I Been Pwned (HIBP) website to check if your email address has appeared in this or any other breaches.
  • Change Your Password: Immediately change the passwords for your Suno and Paidwork accounts, as well as for any other accounts where you used the same password. Use strong, unique passwords for each platform.
  • Enable Two-Factor Authentication (2FA): Activate 2FA on all your accounts where it's available. This adds an extra layer of security that prevents unauthorized access even if your password is stolen.
  • Monitor Your Financial Activity: Paidwork users should carefully review their bank account statements, and Suno users should check the credit card statements for the card used for Stripe transactions. If you see any suspicious activity, contact your bank immediately.
  • Be Wary of Phishing Attacks: Be extremely skeptical of messages you receive via email, SMS, or phone calls asking for personal information or money. Attackers can use the leaked information to create personalized and convincing scam scenarios. Avoid clicking on links in messages claiming to be from these companies.

What the Companies Are Saying

SecurityWeek reached out to both companies for comment. There has been no response from Suno yet.

Paidwork, however, provided the following statement to SecurityWeek: "We are aware of the Have I Been Pwned report but, at this time, Paidwork has no confirmed evidence that our systems or user accounts were compromised in the incident you referenced. We take reports like this seriously and have already escalated the matter to our security team for investigation."

Paidwork's statement indicates that it has not yet confirmed the breach and is conducting an internal investigation. However, the fact that the data has been verified by a reliable source like HIBP necessitates that users take precautions.

Source

https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.