Skip to main content
Live
Main content

Suno scraped 2 million YouTube Music clips to train its AI, leaked files show

Hacked source code reveals the AI music generator pulled from YouTube Music, Deezer, Genius, and IMSLP, backing a key RIAA allegation.

Jaeden Schafer
Editor in Chief · · 5 min read
Suno scraped 2 million YouTube Music clips to train its AI, leaked files show

Suno scraped 2,013,545 YouTube Music clips, hundreds of thousands of hours of additional YouTube Music audio, and thousands of hours from Deezer, Genius, and five other platforms to train its AI music generator, according to source code obtained in a hacking incident and reviewed by 404 Media. The leak, published July 15, 2026, marks the first documented look inside a training pipeline Suno has spent two years refusing to describe in court.

The materials came from a hacker identified as ellie.191 and include Suno source code dating from 2023 and 2024, along with explicit scraping instructions targeting YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and the International Music Score Library Project. Additional code shows Suno pursued roughly 1 million hours of podcasts through PodcastIndex and hundreds of hours of MuseScore lyrics.

One file lists the third-party data broker Bright Data as the vendor Suno used to pull tracks from YouTube. Other snippets show queries designed to surface a cappella versions of songs, a technique that isolates vocals for training generative vocal models. Both details go directly to the Recording Industry Association of America's amended complaint last year, which alleged Suno unlawfully circumvented YouTube's copyright protections by stream-ripping tracks.

Key facts

  • 01Leaked Suno source code shows the AI music generator consumed 2,013,545 YouTube Music clips as of the file's last update.
  • 02Training datasets included hundreds of thousands of hours of YouTube Music and thousands of hours from Deezer, Genius, IMSLP, Jamendo, and Pond5.
  • 03Suno also sought roughly 1 million hours of podcasts via PodcastIndex, and used third-party firm Bright Data to scrape YouTube.
  • 04The RIAA amended its lawsuit last year to allege Suno stream-ripped YouTube tracks, circumventing platform copyright protections.
  • 05A November 2025 hack exposed customer emails, phone numbers, and Stripe payment details; Suno declined to notify affected users.

Suno has already conceded, in filings responding to the RIAA suit, that it trained on copyrighted music. Its defense rests on fair use — the argument that ingesting publicly accessible audio to train a model is transformative and legally protected. The leaked scraping instructions do not change that legal theory, but they do give the RIAA a factual record of exactly which platforms were tapped and at what scale, which is harder to litigate around than an abstract disclosure.

A Suno spokesperson repeated the fair-use framing in a statement to 404 Media, saying the models were trained on publicly available music files and related metadata accessible on third-party websites on the open internet. The company did not address the specific volume figures or the use of Bright Data.

The same breach also exposed customer data, including email addresses, phone numbers, and Stripe payment details. Suno told 404 Media it became aware of a security incident in November 2025 and moved to contain it, adding that the exposed code was outdated and that the company does not hold full credit-card numbers in Stripe. Several customers contacted by 404 Media confirmed they were Suno users and said they had never been notified of a breach.

Suno's position is that individual notifications were not legally required given the type of information involved. That position sits at the edge of state-level breach-notification statutes, several of which require notice when contact information is exposed alongside payment identifiers, even truncated ones. Whether regulators pursue the point may depend on how many customers were affected — a number Suno has not disclosed.

Based on the limited nature of the customer information believed to be involved, we determined that individual notifications were not warranted under applicable privacy laws.
Suno spokesperson, Statement to 404 Media

The training-data disclosure lands at a delicate moment for the wider AI music category. Suno and rivals have been pitching licensing deals to labels while simultaneously arguing in court that no license is required. Concrete numbers — 2,013,545 clips from one platform alone — make that dual posture harder to sustain in negotiations. Labels now have a scale figure to anchor damages calculations against, and a documented vendor relationship (Bright Data) to subpoena.

Related · from this week
Artists press courts on AI training data, and start winning
Jaeden Schafer · 5 min read →

The leak does not by itself resolve the fair-use question, which will likely reach an appellate court regardless of how the RIAA case is decided at trial. Suno may still prevail on the legal theory. What the company loses in the interim is narrative control: the training set is no longer a black box the court has to imagine, and every future disclosure will be measured against the leaked files.

For the AI music market, the practical read is that training-data provenance is about to become a contract term, not a research footnote. Enterprise buyers evaluating generative music tools now have a template for the questions to ask — which platforms, which vendors, how many hours, under what license — and vendors that cannot answer cleanly will lose deals to those that can. Suno's fair-use argument may hold up in court, but the commercial cost of the leak is already priced in.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Artists press courts on AI training data, and start winning

Anthropic's $1.5B settlement is the largest copyright payout ever; suits against Google, Meta, Stability, and Suno keep multiplying.

Jaeden Schafer5 min read
Suno hack exposes source code suggesting YouTube scraping for AI training
Security

Suno hack exposes source code suggesting YouTube scraping for AI training

A November 2025 breach at the AI music generator surfaced code pointing to YouTube Music, Deezer, and Genius as training sources.

Jaeden Schafer4 min read
OpenAI logo
Security

OpenAI faces sanctions bid after allegedly hiding 78M ChatGPT logs from NYT

News plaintiffs say OpenAI concealed pre-searched log samples for two years while claiming the searches were technically infeasible.

Jaeden Schafer5 min read