Leaked hack deepens clash over whether Suno’s AI music training is fair use or mass copyright theft

Hacked files, reported by 404 Media, allegedly show that AI music generator Suno trained its models on millions of songs and lyrics scraped from platforms including YouTube Music, Deezer, and Genius. The leak appears to support allegations in lawsuits that Suno used copyrighted materials without permission.
Leaked hack deepens clash over whether Suno’s AI music training is fair use or mass copyright theft

Leaked hack deepens clash over whether Suno’s AI music training is fair use or mass copyright theft
An alleged hack of AI music generator Suno is intensifying a legal and ethical fight over whether training powerful music models on copyrighted songs is innovative fair use or large‑scale digital theft.

Timeline of the leak and legal fight

In November 2025, a hacker says they launched a supply chain attack, using an employee’s credentials to access Suno’s internal systems and source code. According to that source code, Suno allegedly scraped “decades of audio” from platforms including YouTube Music, Deezer, Genius, stock music libraries, and podcast RSS feeds to train its models.

By mid-2024, major record labels had already filed lawsuits against Suno, accusing it of using copyrighted recordings without permission and even “stream ripping” tracks from YouTube in violation of the Digital Millennium Copyright Act (DMCA) and YouTube’s terms of service.

On July 15, 2026, new reporting based on the hacked files revealed detailed scraping instructions and counts, including a file noting that Suno had ingested over 2 million YouTube Music clips. The materials also indicate Suno used a third‑party company, Bright Data, to pull audio and in some cases sought out a cappella versions of songs to isolate vocals.

Competing perspectives

Suno has publicly argued that it trains on “publicly available music files” and that using copyrighted material for AI training is protected under the fair use doctrine, a flexible exception in U.S. copyright law.

Record labels and rights holders counter that deliberately bypassing YouTube’s technical protections is illegal under the DMCA, regardless of any fair‑use claim, and say the scraped catalog represents “millions of songs” taken without consent.

Privacy concerns add another layer: the hacker says they accessed customer emails, phone numbers, and partial credit card numbers via Stripe, but Suno did not notify users, calling it a “limited security incident that was quickly contained.”

The leaked material now sits at the center of both debates—over how AI models should be trained and how accountable fast‑growing AI startups must be when their internal systems are breached.

Continue reading https://foxvector.com/stories/019f6801-ed7c-113e-720b-1dd73cd608e6

Write a comment