Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
A verified HIBP corpus associated with Suno; the victim’s quoted statement says the incident did not compromise sensitive personal information. [1]
A cited record reports 55,282,226 records (Unique email addresses in HIBP’s verified corpus; not a Suno-confirmed affected-person, customer, account, purchase, or total-row count; as of 2026-07-20). [1]
Timeline
Documented event
HIBP’s day-level BreachDate; Suno’s quoted statement confirms only November 2025, so the exact day remains HIBP-specific.
[1]Public disclosure
Publication date of PC Gamer’s report containing Suno’s quoted statement; not necessarily Suno’s earliest private or public disclosure.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
HIBP marked the Suno incident record verified and not fabricated. A Suno spokesperson said the company determined in November 2025 that it had experienced a limited security incident, quickly contained it, investigated, and found that it primarily involved outdated source code no longer in use. Suno’s quoted statement said its investigation verified that no sensitive personal information was compromised. The evidence ledger retains 5 disputed claims with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
