Suno scraped 2,013,545 YouTube Music clips, hundreds of thousands of hours of additional YouTube Music audio, and thousands of hours from Deezer, Genius, and five other platforms to train its AI music generator, according to source code obtained in a hacking incident and reviewed by 404 Media. The leak, published July 15, 2026, marks the first documented look inside a training pipeline Suno has spent two years refusing to describe in court.
The materials came from a hacker identified as ellie.191 and include Suno source code dating from 2023 and 2024, along with explicit scraping instructions targeting YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and the International Music Score Library Project. Additional code shows Suno pursued roughly 1 million hours of podcasts through PodcastIndex and hundreds of hours of MuseScore lyrics.
One file lists the third-party data broker Bright Data as the vendor Suno used to pull tracks from YouTube. Other snippets show queries designed to surface a cappella versions of songs, a technique that isolates vocals for training generative vocal models. Both details go directly to the Recording Industry Association of America's amended complaint last year, which alleged Suno unlawfully circumvented YouTube's copyright protections by stream-ripping tracks.
Key facts
- 01Leaked Suno source code shows the AI music generator consumed 2,013,545 YouTube Music clips as of the file's last update.
- 02Training datasets included hundreds of thousands of hours of YouTube Music and thousands of hours from Deezer, Genius, IMSLP, Jamendo, and Pond5.
- 03Suno also sought roughly 1 million hours of podcasts via PodcastIndex, and used third-party firm Bright Data to scrape YouTube.
- 04The RIAA amended its lawsuit last year to allege Suno stream-ripped YouTube tracks, circumventing platform copyright protections.
- 05A November 2025 hack exposed customer emails, phone numbers, and Stripe payment details; Suno declined to notify affected users.
Suno has already conceded, in filings responding to the RIAA suit, that it trained on copyrighted music. Its defense rests on fair use — the argument that ingesting publicly accessible audio to train a model is transformative and legally protected. The leaked scraping instructions do not change that legal theory, but they do give the RIAA a factual record of exactly which platforms were tapped and at what scale, which is harder to litigate around than an abstract disclosure.
A Suno spokesperson repeated the fair-use framing in a statement to 404 Media, saying the models were trained on publicly available music files and related metadata accessible on third-party websites on the open internet. The company did not address the specific volume figures or the use of Bright Data.
The same breach also exposed customer data, including email addresses, phone numbers, and Stripe payment details. Suno told 404 Media it became aware of a security incident in November 2025 and moved to contain it, adding that the exposed code was outdated and that the company does not hold full credit-card numbers in Stripe. Several customers contacted by 404 Media confirmed they were Suno users and said they had never been notified of a breach.
Suno's position is that individual notifications were not legally required given the type of information involved. That position sits at the edge of state-level breach-notification statutes, several of which require notice when contact information is exposed alongside payment identifiers, even truncated ones. Whether regulators pursue the point may depend on how many customers were affected — a number Suno has not disclosed.
“Based on the limited nature of the customer information believed to be involved, we determined that individual notifications were not warranted under applicable privacy laws.”— Suno spokesperson, Statement to 404 Media
The training-data disclosure lands at a delicate moment for the wider AI music category. Suno and rivals have been pitching licensing deals to labels while simultaneously arguing in court that no license is required. Concrete numbers — 2,013,545 clips from one platform alone — make that dual posture harder to sustain in negotiations. Labels now have a scale figure to anchor damages calculations against, and a documented vendor relationship (Bright Data) to subpoena.
The leak does not by itself resolve the fair-use question, which will likely reach an appellate court regardless of how the RIAA case is decided at trial. Suno may still prevail on the legal theory. What the company loses in the interim is narrative control: the training set is no longer a black box the court has to imagine, and every future disclosure will be measured against the leaked files.
For the AI music market, the practical read is that training-data provenance is about to become a contract term, not a research footnote. Enterprise buyers evaluating generative music tools now have a template for the questions to ask — which platforms, which vendors, how many hours, under what license — and vendors that cannot answer cleanly will lose deals to those that can. Suno's fair-use argument may hold up in court, but the commercial cost of the leak is already priced in.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




