A breach of AI music generator Suno exposed personal data from 55 million users, according to Have I Been Pwned. Stolen information includes names, phone numbers, and physical addresses.
Suno, a platform that uses artificial intelligence to generate music, suffered a significant data breach affecting millions of its users. The incident was confirmed by Have I Been Pwned, a security database that tracks compromised accounts and data breaches.
The compromised data includes names, phone numbers, and physical addresses belonging to 55 million users. The breach represents a substantial exposure of personal identifying information that could be used for targeted attacks, spam campaigns, or identity theft.
Have I Been Pwned, operated by security researcher Troy Hunt, maintains a comprehensive database of breaches and allows users to check if their information has been compromised. The platform's confirmation of this breach adds credibility to the disclosure and serves as a public alert for affected users.
Suno has not yet issued a public statement regarding the breach or details about how the compromise occurred. The company has not disclosed whether the breach was discovered internally or reported by security researchers.
Users of the AI music generator should take precautions following this disclosure. Those affected may receive unsolicited communications or targeted phishing attempts using their exposed personal information. Experts recommend monitoring credit reports and remaining alert for suspicious activity.
This breach highlights ongoing security challenges for AI-focused platforms that have rapidly expanded user bases. As AI tools gain mainstream adoption, the security infrastructure protecting user data remains inconsistent across the industry.
Affected users can check Have I Been Pwned to confirm whether their data was included in the breach. Suno users should consider changing passwords and enabling two-factor authentication on their accounts if available.
N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform. The flaw is being actively exploited in ongoing attacks.
QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.
Threat actors are deploying invisible Unicode characters in phishing campaigns to evade email security systems. The ASCII smuggling technique allows attackers to conceal malicious content from detection tools.
A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.