Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Two separate data breaches have exposed the personal information of tens of millions of users across Suno, an AI music generator, and Paidwork, a gig-work platform. Hackers obtained user data and source code, leading to the exposure of email addresses, payment details, and other sensitive information. The incidents highlight growing risks associated with AI-driven platforms and the increasing sophistication of cyberattacks.
Two major data breaches have impacted Suno and Paidwork, exposing the details of a combined 77.3 million user accounts. Hackers targeted Suno in November 2025, gaining access to the company’s source code and a substantial amount of user data. This included 55.3 million unique email addresses, alongside phone numbers and a significant number of Stripe payment records containing names, physical addresses, purchase amounts, and partial card details (card type, expiration date, and last 4 digits).
As for Paidwork, the platform experienced a breach in March 2026, resulting in the leak of an 11 GB database containing approximately 23.3 million user records. This data included email addresses, names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, and financial transaction information. The stolen source code from Suno revealed that the company had been scraping music and podcasts from platforms like Deezer, YouTube, and Genius.
SecurityWeek has contacted both Suno and Paidwork for comment on the incidents. The breaches underscore the vulnerabilities present in AI-driven platforms and the ongoing threat landscape for gig-economy workers.