Tens of millions of users of two popular online platforms have had their personal data exposed in massive data breaches.
Suno, an artificial intelligence music generator, and Paidwork, a gig-work platform, have both been targeted by hackers who stole sensitive information from their databases. The breach is believed to have occurred in November 2025 for Suno, but only came to light earlier this month when the source code and user data were leaked online.
The stolen data includes email addresses, phone numbers, payment records, and even partial credit card details. For Paidwork, hackers claimed to have targeted the company in March 2026, and an 11 GB database was allegedly stolen, containing information on around 22 million users.
Have I Been Pwned (HIBP), a data breach notification service, has analyzed the leaked data and identified tens of millions of unique email addresses associated with Suno and Paidwork accounts. The compromised user data also includes names, physical addresses, dates of birth, and phone numbers.
The way these breaches occurred is still not entirely clear. However, it’s believed that hackers exploited vulnerabilities in the systems to gain access to the sensitive information. Both companies have been contacted for comment but so far only Paidwork has responded, stating they are aware of the report and are investigating the matter further.
This massive data breach raises significant concerns about user privacy and security. With tens of millions of records compromised, it’s likely that many users will be at risk of identity theft or other forms of cybercrime. It also highlights the importance of companies taking robust measures to protect their systems from hackers.
In practical terms, this means that users who have accounts with Suno or Paidwork should be vigilant and monitor their bank statements for any suspicious activity. If they notice anything unusual, they should report it to their banks immediately.
Additionally, both companies should take immediate action to secure their systems and prevent further breaches. This includes implementing robust security measures such as multi-factor authentication, regular software updates, and employee training on cybersecurity best practices.
Ultimately, this data breach serves as a reminder that even the most popular online platforms are vulnerable to cyber attacks. It’s essential for users to remain cautious when sharing personal information online and for companies to prioritize their customers’ security above all else.
Source: SecurityWeek — 2026-07-22