TLDRocket
Sign in

Hack suggests AI music generator Suno scraped YouTube for training data

TechCrunch Amanda Silberling Covered by 2 sources

A hacker says a 2025 breach exposed Suno's source code, revealing it scraped YouTube, Deezer, Genius and podcast feeds for training data. That's the exact kind of scraping record labels are already suing Suno over — and Suno never told customers about the breach.

Based on reporting by TechCrunch, Amanda Silberling — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Suno has spent months telling courts and reporters that it trains on "publicly available music files," leaning on fair use as its shield. A hack reported by 404 Media complicates that story considerably. The hacker claims they got into an employee's credentials back in November 2025 through a supply chain attack, then poked around in source code that allegedly shows Suno pulling decades of audio from YouTube Music, Deezer, Genius, stock libraries, and podcast RSS feeds.

The distinction matters more than it might seem. "Publicly available" and "scraped past YouTube's anti-scraping protections" are not the same legal category. Major record labels suing Suno argue the latter runs straight into the Digital Millennium Copyright Act, which bars deliberately circumventing a platform's technical protections, on top of breaching YouTube's own terms of service. If the leaked code holds up as evidence, Suno's fair-use defense gets a lot harder to make with a straight face.

Suno isn't alone here. Udio, its closest rival in AI-generated music, faces near-identical accusations of pulling from YouTube. And YouTube's parent, Google, has its own scraping headaches, fighting off copyright claims from book publishers over training data. The whole generative AI industry seems to be running the same playbook: build first, scrape what's available, and let the lawyers sort out fair use later.

The breach also cost Suno more than just legal exposure. The hacker says they grabbed customer emails, phone numbers, and partial credit card numbers stored in Stripe. Suno never told users about any of it, calling it a "limited security incident that was quickly contained." Nine months of silence on a breach involving payment data is a strange definition of contained, and it's the kind of gap that regulators and plaintiffs' lawyers tend to notice.

My take — AI-written commentary, not fact-checked reporting

Suno's fair-use argument was already shaky, but doing it while allegedly defeating YouTube's anti-scraping tech turns a gray area into a straightforward DMCA problem. I'm not surprised a music AI company hid a breach for nine months — disclosure rules in this industry are basically vibes-based — but pair that with the scraping allegations and you get a company that seems to treat both copyright law and customer data as optional details on the way to a product launch.

Read more about this at: TechCrunch

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.