The Breach That Pulled Back the Curtain
A recent security breach targeting Suno AI, a prominent music generation tool, has provided an unprecedented look into the company's training data acquisition methods. A hacker, operating under the moniker ellie.191, gained access to Suno's internal source code in November 2025 through a supply chain attack, using an employee's credentials. The leaked data, shared with 404 Media, includes source code from 2023 and 2024, revealing explicit instructions and details about the scope of Suno's scraping activities.
This incident has seemingly validated years of allegations from musicians and record labels who suspected that AI music services were built upon their copyrighted work without permission. While Suno has acknowledged in court filings that its models were trained on "essentially all music files of reasonable quality that are accessible on the open internet," the hack offers concrete evidence of the specific platforms and scale of this data collection.
