Desk live·
ForensicPost
AI/AI/File 26-0604

The Source Code Disclosed What the Training Data Was

A source code breach at the music generation service Suno reportedly revealed scraped training material alongside user data for around 55 million people. Two very different disclosures in one incident.

Constructed geometry · not a chart of case data
TargetSuno
ActorUnattributed
D. Kennedy10 min readConfidence: medium1 source reviewed

A breach at the AI music generation service Suno was reported to involve source code that revealed scraped training data, alongside user information — names, addresses and partial payment card data — for around 55 million users. Reporting indicates the company confirmed the incident without making a public statement.

Two exposures sit in that paragraph, and they belong to different parties.

The User Data Is The Conventional Half

Fifty-five million people with names, addresses and partial card data is a serious but familiar exposure, with familiar remediation. It is the part a notification regime is built to handle.

The absence of a public statement is the notable feature. Where a company confirms privately and says nothing publicly, affected users learn from reporting rather than from the organisation holding their data.

The Training Data Disclosure Is Not A Security Question

What the code reportedly revealed about training material is a different category. Nobody’s personal data was exposed by it; what was exposed was a set of commercial and legal facts the company had chosen not to publish.

This desk covers evidence, and it is worth being precise about what kind this is. A breach that reveals corporate conduct is not a security failure with a legal footnote — it is two events that happen to share a cause, and conflating them serves nobody.

Model Companies Hold An Unusual Pairing

Generative services combine a consumer platform’s user estate with a research organisation’s sensitive corpus. The first attracts ordinary criminal interest; the second attracts interest from litigants, regulators and competitors.

Those are different adversaries with different objectives, and a single code repository can satisfy both. Graded medium: the incident and figures are consistently reported, and the company has not published its own account.

How we reported this

Compiled from public reporting, listed below. We are not characterising the legal status of any training practice; we report that the disclosure occurred. We did not review the code or the user data. Corrections: corrections@forensicpost.com.

Sources
  1. Data breach roundup (July 17–23, 2026)Privacy Guides
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary