All stories
AI

Hacking Incident Exposes Suno's Alleged Copyright Scraping for AI Music Training

A hacking incident has revealed Suno, a leading AI music generator, allegedly scraped millions of copyrighted songs and lyrics from platforms like YouTube Music, Deezer, and Genius to train its models, confirming industry suspicions and fueling major lawsuits.

By TECH NEWS Editorial·Source:The Verge AI·4 min read·5d ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Hacking Incident Exposes Suno's Alleged Copyright Scraping for AI Music Training

A hacking incident has exposed Suno, a leading AI music generator, for allegedly scraping millions of copyrighted songs and lyrics from major online audio platforms, including YouTube Music, Deezer, and Genius, to train its artificial intelligence models. The breach, reported by 404 Media, revealed internal source code from 2023 and 2024 detailing specific scraping instructions and an inventory of ingested content, confirming long-held suspicions from the music industry. Among the disclosed figures are over 2 million music clips from YouTube Music, totaling 113,879 hours, along with 12,287 hours from Deezer, 17,615 hours from Genius, and substantial volumes from other sources like Pond5, Jamendo, and even podcasts via RSS feeds. This revelation follows Suno's previous admission in court filings that its models were trained on "tens of millions of recordings" from "essentially all music files of reasonable quality that are accessible on the open internet".

The implications of this data leak extend far beyond Suno itself, striking at the core of the burgeoning generative AI industry and its contentious relationship with intellectual property. While Suno confirmed a "limited security incident" in November 2025 involving "outdated source code" and stated no "sensitive personal information was compromised" or required individual notification, the hacker, identified as "ellie.191," claimed access to customer emails, phone numbers, and Stripe payment details, with some users corroborating this to 404 Media. This discrepancy raises immediate concerns about data security and transparency from AI developers. More critically, the leaked data provides concrete evidence for the "mass infringement" lawsuits filed by the Recording Industry Association of America (RIAA) on behalf of Universal Music Group, Sony Music Entertainment, and Warner Music Group against Suno and rival AI music generator Udio. Warner Music Group has already settled with Suno and entered a licensing agreement in November 2025, signaling a potential shift towards a "walled garden" model where major labels license their catalogs under controlled conditions.

This controversy underscores a fundamental tension: AI companies argue that training on copyrighted material constitutes "fair use," a legal doctrine intended to permit limited use of copyrighted material without permission for purposes such as criticism, commentary, news reporting, teaching, scholarship, or research. However, the music industry asserts that industrial-scale ingestion of entire works for commercial gain is anything but fair, particularly when the AI output directly competes with human artistry. The RIAA's attempt to add over 61,000 recordings to its lawsuit against Suno, potentially escalating damages to over $9 billion, highlights the scale of financial exposure and the industry's determination to enforce copyright. The legal landscape remains largely undefined, with courts still grappling with how existing copyright laws apply to AI training data. For instance, the US Copyright Office ruled in January 2025 that 100% AI-generated content cannot be copyrighted, placing a significant limitation on the proprietary claims of AI-created works.

The revelation of Suno's scraping practices also casts a critical light on the broader AI music ecosystem. Competitors like Google's Lyria 3 and Udio face similar allegations of training on copyrighted YouTube content. The Atlantic's "AI Watchdog" project has further unearthed four searchable databases containing over 21 million songs, including works from global superstars like Taylor Swift and Bad Bunny alongside independent artists, that are circulating among AI developers as training data. These datasets often comprise mere links to streaming platforms, with developers employing tools to bypass conventional monetization and access controls, effectively "stream-ripping" content. This practice undermines the economic models of artists and platforms alike, devaluing creative output and making it increasingly difficult for human artists to compete for visibility and income in a market potentially saturated with royalty-free, machine-made tracks.

Looking ahead, the Suno data leak and ongoing legal battles are pivotal in shaping the future of AI music. The outcome of these lawsuits, particularly the fair use defense, will set critical precedents for how AI models can be trained and how artists will be compensated. We are likely to see a continued push towards licensing agreements, as demonstrated by Warner Music Group's deal with Suno and Udio's prior settlements with major labels, creating a more regulated but potentially less open ecosystem. Furthermore, increasing transparency regarding AI training data, perhaps driven by tools like The Atlantic's AI Watchdog, will empower artists to track the use of their work and advocate for their rights. The industry may also witness a bifurcation: heavily licensed, corporate-backed AI music on one side, and a struggling independent scene battling for authenticity and fair compensation on the other. Ultimately, the challenge is to harness the transformative potential of AI without erasing the human creativity and livelihoods that form the bedrock of the music industry.

Watch (Shorts)