Hackers Stole Data on 78 Million Users From AI Music App Suno and Gig Platform Paidwork

Two separate breaches exposed names, payment details, bank account numbers, and tens of millions of email addresses. Here is what happened and what affected users should do.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Hackers stole data on 55.3 million Suno accounts, including partial payment card details, according to Have I Been Pwned's analysis published in June 2026.
  • A separate breach at Paidwork, a platform where users complete small paid tasks online, exposed 23.3 million unique email addresses along with bank account numbers and financial transaction records.
  • Suno's breach, which occurred in November 2025, also exposed tens of thousands of Stripe payment records containing names, physical addresses, and the last four digits of card numbers.
  • The Paidwork attackers leaked an 11 GB database in late May 2026, claiming it held roughly 22 million user records.

Two popular online platforms are dealing with serious data breaches that together affect close to 80 million accounts. Suno, an AI-powered music generator that lets users create songs by typing text prompts, was hit in November 2025. Paidwork, a site where people complete small digital jobs for money, was targeted in March 2026.

Neither company had publicly confirmed the breaches at the time of writing. SecurityWeek first reported the scale of both incidents.

What did the criminals actually take?

Plenty. For Suno, Have I Been Pwned (HIBP), a free service that tells people whether their personal data has appeared in a known breach, identified 55.3 million unique email addresses in the stolen data. Beyond email addresses, the haul included phone numbers and tens of thousands of records from Stripe, an online payment processor. Those Stripe records contained names, home addresses, purchase amounts, card types, expiry dates, and the last four digits of card numbers.

The Suno breach also exposed something unexpected: source code, meaning the private instructions that make the software run. That code reportedly showed Suno had been scraping, which means automatically copying content without permission, music and podcasts from Deezer, YouTube, and Genius.

The Paidwork breach is arguably more damaging for the individuals involved. HIBP found 23.3 million unique email addresses in the leaked database, but the attackers also walked out with names, dates of birth, phone numbers, physical addresses, password hashes (scrambled versions of passwords that can sometimes be cracked), bank account numbers, and financial transaction records.

Bank account numbers in a breach are a serious escalation. Combined with a name and address, that information is enough for criminals to attempt fraudulent transfers or impersonation scams.

If you have an account on either platform, change your password immediately and use a different password on every other site where you reused the same one. If you used Paidwork, monitor your bank statements closely for any transactions you do not recognise and consider alerting your bank. Be suspicious of any emails or texts that claim to be from Suno or Paidwork asking you to verify details.

The failure mode here is a familiar one: large amounts of sensitive data sitting in a single database, with no public indication that users were notified promptly. One thing the post-mortem will say is that payment data and bank details had no business living in the same store as profile information.

In practice, the people most at risk are Paidwork users who shared banking details to receive their earnings.

© 2026 Threat Vectr