securitylab_nJuly 16, 2026🇷🇺Translated from Russian

Hacker Leaks Suno Source Code Exposing Massive Scraping of 2 Million YouTube Music Tracks and Customer Data Breach

A hacker operating under the pseudonym ellie.191 has leaked the internal source code of Suno, one of the largest AI-powered music generation platforms, to the investigative outlet 404 Media. The disclosure reveals how the company systematically scraped millions of copyrighted tracks and podcasts to train its generative models.

The leaked materials, believed to originate from 2023 and 2024, contain detailed instructions for downloading content and precise records of dataset sizes. According to the code, Suno obtained more than 2 million music fragments from YouTube Music alone. Additional sources listed in the files include Pond5, Jamendo, Freesound, the International Music Score Library Project, and MuseScore.

One dataset comprised over 152,000 hours of labeled audio from YouTube Music, while another collection from the same platform added 114,000 hours. Approximately 62,000 hours came from Pond5 and more than 12,000 hours from Deezer. Separate scripts were designed to locate karaoke-style versions of songs on YouTube to extract isolated vocals.

To facilitate large-scale downloads, Suno relied on proxy infrastructure provided by Bright Data. Another tool identified 420,000 podcasts and prepared nearly 1 million hours of recordings for ingestion.

The publication corroborates allegations previously made by the Recording Industry Association of America, which accused Suno of bypassing YouTube’s technical protections to copy protected works. Although Suno has publicly stated it trained on tens of millions of publicly available recordings under a fair-use rationale, rights holders continue to challenge this position in court.

In addition to the training data, the hacker claims to have obtained records belonging to hundreds of thousands of Suno customers, including email addresses, phone numbers, and partial payment information processed through Stripe. Several affected users have already verified to 404 Media that the exposed phone numbers match their accounts and that they never received breach notifications.

Suno responded that it detected a limited intrusion in November 2025 and quickly contained it. The company maintains that only outdated source code was accessed and denies that any sensitive personal or full payment card data was exposed. The hacker stated that access was achieved through an employee account infected by the Shai-Hulud worm, which harvested GitHub and cloud-service credentials, and that the operation was conducted out of general curiosity rather than targeted malice.

Related articles

AntiMalwareData Breaches & Leaks

Kaspersky MDR Adds Automatic Correlation with Leaked Credentials via Digital Footprint Intelligence

Kaspersky has updated its Managed Detection and Response service to automatically match security events against data from compromised logins and passwords. The enhancement integrates Kaspersky Digital Footprint Intelligence to provide analysts with additional context when suspicious activity coincides with known credential leaks. According to the company, a quarter of attacks investigated in 2025 began with the use of stolen credentials. The update also introduces notifications for asset protection status, allowing administrators to address connectivity or telemetry issues that could affect monitoring quality. Managed service providers can now configure per-client license usage limits, and the service adds support for Kaspersky Embedded Systems Security for Linux 4.0. The MDR platform continues to deliver 24/7 infrastructure monitoring, threat hunting, incident investigation, and response capabilities.

AntiMalwareData Breaches & Leaks

Hacktivist Group Cyberleek Leaks Alleged GTA VI Gameplay and Map Details in Protest Against Digital-Only Releases

A hacktivist collective calling itself Cyberleek has released two purported gameplay clips from GTA VI along with images that may depict the full map of Leonida state. The group claims the leak is a protest against Rockstar's decision to sell physical editions that contain only a download code rather than an actual disc. Cyberleek is also demanding an end to digital pre-orders, the practice of selling built-in content as DLC, and mandatory online connectivity for single-player modes. Rockstar and parent company Take-Two have already filed DMCA takedown requests, which some observers view as indirect confirmation of the material's authenticity. The footage reportedly shows basketball mechanics, vehicle customization, trunk-opening animations, a stamina meter, and an honor system reminiscent of Red Dead Redemption 2. The alleged map includes five counties, an extensive rail network, and numerous small islands. At the same time, Cyberleek is promoting a Solana-based token and soliciting donations, prompting several outlets to question whether the operation is partly a cryptocurrency marketing scheme.

AntiMalwareData Breaches & Leaks

Russian Medical Data Leaks Explode in July: 88 Million Records Exposed

In July 2026 more than 100 million records containing personal data of Russian citizens appeared in open access. Experts from Perspektivny Monitoring recorded 17 separate leaks originating from commercial organizations, online platforms, government bodies, e-commerce stores and medical institutions. The medical sector accounted for the overwhelming majority with 88.37 million records leaked, a sharp increase from 1.7 million in June. Two major incidents, one involving a large medical information system, drove the spike. Head of cyber threat research Nikolay Galkin stated that medical data has now leaked for four consecutive months and that attackers are deliberately targeting highly sensitive information. Other sectors also suffered losses, with 11.12 million records from commercial entities, 8.45 million from online platforms, 8.36 million from government organizations and 2.1 million from internet shops. Stolen databases are routinely traded in messenger channels and dark web marketplaces for use in fraud schemes.

BoletimSecData Breaches & Leaks

SplitVPN Data Breach Exposes Personal Information of 865,000 Users

A data breach at the Russian VPN provider SplitVPN, formerly known as NotVPN, has exposed the personal details of approximately 865,000 users. The incident, which occurred in July 2026, involved a 17 GB SQL database containing emails, IP addresses, geolocation data, and partial payment card information. The stolen material was later distributed on a cybercrime forum, revealing 23.4 million user records, 13.6 million devices, and 2.6 million payment entries. Nearly 58 million connection logs spanning June 2025 to 21 July 2026 were also included, contradicting the company’s previous no-logs policy. The exposure is particularly concerning for users relying on the service to evade censorship and surveillance.