Suno Hack Exposes Massive YouTube and Deezer Scraping for AI Training
More than two million audio clips for YouTube Music alone, and hundreds of thousands of hours of music in total: a Suno hack has revealed the full scale of the data haul used to train its AI. The data, shared with 404media, details where the training data used by the AI music-generation startup came from. Put simply, they did not do things halfway.
That Suno trained on copyrighted works is nothing new. The AI company had already admitted as much in 2024, as part of lawsuits filed in the United States by the recording industry. It acknowledged using "practically every reasonably quality music file available on the open internet", or "tens of millions of recordings" (comments reported by 404media). What was unknown was the exact scale of the collection and how it was gathered, but a hack has now changed everything.
More than two million clips: industrial-scale scraping
According to 404media, which reviewed the data provided by the hacker, the haul includes source code dated 2023 and 2024, along with scraping instructions and details on part of the collected volumes. A comment in one file lists the targeted sources and specifies that non-music content will be filtered out. For example, a file named youtube_music shows that 2,013,545 music clips had been ingested at the time of its last update.
Another file contains statistics with the number of hours accumulated per dataset:
- 152,162 hours for
ytm_tagged - 113,879 hours for
youtube_music - 62,117 hours for
pond5_music - 19,514 hours for
imslp(public domain sheet music from the International Music Score Library Project) - 17,615 hours for
genius_hq - 12,287 hours for
deezer - 3,726 hours for
jamendo - 410 hours for
freesound - 103 hours for
musescore_lyrics

These catalogs are joined by podcasts collected via their RSS feeds. A true industrial-scale scraping operation, drawing on a wide variety of sources: mainstream platforms (YouTube Music, Deezer), royalty-free or stock music libraries (Jamendo, Freesound, Pond5), and even Genius, which specializes in lyrics.
Even so, Suno appears to have carried out targeted, methodical scraping, prioritizing a cappella versions of songs. This would make it easier to isolate and analyze vocals, which would be more useful for training an AI. To carry out the scraping, Suno reportedly used Bright Data, a company specializing in automated data collection.
Pond5 is also particularly interesting for Suno: it is a music and sound effects library owned by Shutterstock. The platform says it offers 2.6 million tracks, and downloads require a paid subscription. Suno therefore pulled more than 60,000 hours of audio from this platform while bypassing those restrictions. In reality, there is little chance Suno limited itself to training on freely accessible content.
A Shai-Hulud intrusion via an employee’s workstation
To access Suno’s systems, the hacker managed to compromise an employee’s workstation, which then allowed them to hijack access credentials. According to the hacker, who goes by the handle ellie.191, the incident is linked to the Shai-Hulud campaign. For the record, this worm hides inside infected npm packages, spreads from project to project, and along the way steals developers’ secrets: GitHub tokens, API keys, access to cloud environments. This threat has been poisoning the open source ecosystem since fall 2025, with numerous supply chain attacks, a topic I already covered following the wave of npm package compromises.
With these accesses, the hacker reportedly managed to reach two categories of data: on one side, contact information (email address or phone number, depending on what the user provided when signing up), and on the other, billing details tied to Stripe. 404media says it cross-checked part of the sample provided with real subscribers.
For its part, Suno is being less alarmist. The intrusion is said to be linked to a November 2025 security incident, which it describes as limited and quickly contained. According to the company, the leak mainly involved outdated source code that is now out of service. Suno also says it never holds full payment card numbers, which are entrusted to Stripe. What is also problematic is its lack of communication with users whose data was exposed by this intrusion. The startup justifies not warning users by pointing to the limited scope of the exposed information... Not great.
Where Suno may be right is on the timing: November 2025. This lines up with the resurgence of Shai-Hulud around the same period, but that still needs confirmation. What is certain is that Suno has a real appetite for music data, at any cost. This case is likely to reignite tensions between the startup and the music industry.


