The Hack That Exposed AI Music's Massive Data Harvesting
For months, the music industry has suspected that leading AI music generators were built on the backs of human artists without permission. Now, a cyberattack...

For months, the music industry has suspected that leading AI music generators were built on the backs of human artists without permission. Now, a cyberattack has inadvertently provided the receipts. A hacker recently breached Suno, one of the most popular AI music platforms, revealing the staggering scale of the data harvesting that powers its algorithmic melodies.
The leaked internal documents and source code offer a rare, unfiltered look into how AI models are actually trained. According to the data shared by the hacker, Suno didn’t just scrape a few public domain tracks. It ingested a colossal amount of copyrighted material: over 113,000 hours of audio from YouTube Music, 62,000 hours from the stock music library Pond5, and thousands of hours from platforms like Deezer and Genius. The code even detailed specific tactics, such as utilizing proxy networks to bypass scraping restrictions and actively hunting for acapella tracks on YouTube to train the AI on isolated human vocals.
This revelation comes at a critical time. Suno is currently facing major lawsuits from the Recording Industry Association of America (RIAA), which accused the company of unlawfully "stream ripping" decades' worth of popular music. While Suno has maintained that training its AI on open-internet data constitutes "fair use," the hacked files provide concrete evidence of the systematic and targeted nature of their data collection, turning abstract legal arguments into hard numbers.
But the breach isn't just about copyright infringement; it's also a stark warning about data security. The hacker, who gained access through a supply chain attack targeting a single employee, also compromised the personal information of hundreds of thousands of Suno customers. This included emails, phone numbers, and certain payment details. Suno acknowledged the breach but downplayed its severity, stating it mostly involved outdated code and that no highly sensitive personal information was compromised—a conclusion that led them to skip notifying individual users.
This incident pulls back the curtain on the often-messy reality of AI development. It highlights a dual vulnerability in the generative AI boom: the massive, uncompensated extraction of human creativity to build commercial products, and the inherent security risks of hoarding both training data and user information. As AI continues to reshape how we create and consume art, we must confront the hidden costs of this technological magic.
Key Points
- A hacker breached AI music platform Suno, leaking internal code that reveals its training data sources.
- Suno scraped hundreds of thousands of hours of copyrighted music from YouTube, Pond5, and other platforms.
- The cyberattack also compromised the personal data of hundreds of thousands of Suno users.
- The leaked data provides concrete evidence amid ongoing copyright lawsuits from the music industry.
Why It Matters
It provides hard evidence of how AI companies scrape copyrighted material to build commercial models, raising urgent questions about fair use, creator compensation, and data security.
Sources:
更多专栏

OpenAI's First Hardware is a Glowing Dashboard for AI Agents
For years, our interaction with OpenAI's technology has been strictly confined t...

The End of the Blank Search Bar
For a quarter of a century, the Google Images homepage has been a masterclass in...

The Cost of Context: When AI Reads Too Much
When you call a plumber to fix a leaky sink, you expect them to look at the pipe...