Case Filed · D. Mass. No. 1:26-cv-13433

Suno Data Breach Class Action

Frank Richard Rugnetta filed a putative class action against Suno, Inc. over a reported November 2025 data breach involving personal information associated with more than 55 million users.

Why the Suno data breach matters

Public reporting describes a November 2025 security incident in which an attacker obtained Suno source code and customer information. Have I Been Pwned later analyzed the reported dataset and listed 55.3 million unique email addresses. TechCrunch reported that Suno confirmed the incident but had not publicly disclosed it on its website or provided the outlet with a copy of any notice sent to users as of July 21, 2026. On July 28, 2026, Frank Richard Rugnetta filed a class action complaint against Suno. The complaint contains allegations only; no findings have been made.

  1. Reported security incident

    A hacker later claimed that a supply-chain attack exposed an employee's credentials and enabled access to Suno systems. TechCrunch reported that Suno described the event as a limited security incident that was quickly contained.

  2. The incident becomes public

    404 Media reported on breached Suno source code, customer information, and Stripe payment data. TechCrunch reported the same day that Suno had not notified customers about the November incident.

  3. Have I Been Pwned quantifies the dataset

    Have I Been Pwned added the breach to its index and reported 55.3 million unique email addresses, plus phone numbers and tens of thousands of Stripe purchase records.

  4. Suno confirms an incident

    TechCrunch reported that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the number of affected users. The outlet said Suno did not provide a copy of any user notification when asked.

  5. Class action filed

    Frank Richard Rugnetta filed Rugnetta v. Suno, Inc., No. 1:26-cv-13433, in the U.S. District Court for the District of Massachusetts. The complaint contains allegations only; no findings have been made.

What information was reportedly exposed?

Most of the reported corpus consisted of email addresses. Other information was present only for some users or within a smaller set of Stripe purchase records. Public sources do not list passwords or full card numbers as compromised data.

Account identifiers
Email addresses and, for some accounts, phone numbers
Customer details
Names and physical addresses within reported Stripe records
Purchase information
Purchase amounts and related transaction records
Partial card data
Card type, expiration date, and last four digits—not full numbers

Important distinction

Partial card details still create phishing and impersonation risks when combined with names, addresses, and purchase information. The precise information associated with each person may differ.

How Hall Attorneys can help

The complaint proposes a Nationwide Class of people in the United States whose email address or other personal information was included in the dataset obtained from Suno in connection with the November 2025 breach, plus a California Subclass. No class has been certified.

Hall Attorneys is interested in hearing from current and former Suno users, including:

  • Current or former Suno users whose email address appears in the reported dataset
  • People who used a phone number to create or access a Suno account
  • Suno customers whose purchases were processed through Stripe
  • Users receiving targeted phishing, payment-themed messages, or suspicious account communications after the incident

What to preserve if you think your Suno information was exposed

Preserve the records below, but do not send passwords, authentication codes, complete card numbers, or unredacted financial records through ordinary website forms.

Record 1

Suno account records

Save account-creation emails, profile screenshots, subscription information, and any security or privacy communications from Suno. Include dates where possible.

Record 2

Purchase and billing records

Preserve Suno receipts, Stripe receipts, subscription changes, refund records, and card alerts. Redact full card numbers before sharing documents by ordinary email.

Record 3

Suspicious messages

Keep phishing emails, texts, or direct messages that reference Suno, AI music, subscriptions, billing, refunds, account verification, or personal information.

Record 4

Account-security alerts

Save password-reset messages, unfamiliar-login alerts, two-factor authentication prompts, and records of account changes you did not request.

Record 5

Breach-check results

Keep a dated screenshot or PDF if a reputable breach-notification service reports that your email address appears in the Suno dataset.

Record 6

Time, expenses, and harm

Track time spent securing accounts, replacing cards, monitoring transactions, responding to phishing, or addressing identity theft or financial loss.

Claims and relief requested

The complaint pleads five causes of action and requests monetary and prospective relief. These are allegations and requests for relief, not court findings.

  1. Negligence
  2. Breach of implied contract
  3. Breach of the implied covenant of good faith and fair dealing
  4. Unjust enrichment and restitution, pleaded in the alternative
  5. Declaratory and equitable relief concerning security, retention, incident response, and notice
  6. Damages, complete individualized notice, at least five years of appropriate identity-theft, phishing, and account-protection services, and prospective security and data-governance measures

Sources for the Suno case

The filed complaint is the source for the case allegations, claims, proposed classes, and requested relief. Public reporting is separately attributed below.

U.S. District Court, District of Massachusetts ·

Rugnetta v. Suno, Inc. - Class Action Complaint

ECF No. 1 in Case No. 1:26-cv-13433. The complaint states the allegations, proposed classes, pleaded claims, and requested relief.

Read source: Rugnetta v. Suno, Inc. - Class Action Complaint

Have I Been Pwned ·

Suno Data Breach

Lists 55.3 million unique email addresses and the account, purchase, address, and partial payment-card data categories reportedly involved.

Read source: Suno Data Breach

Frequently asked questions

Is this a filed Suno lawsuit?

Yes. Frank Richard Rugnetta filed a class action complaint against Suno, Inc. on July 28, 2026 in the U.S. District Court for the District of Massachusetts. The case is Rugnetta v. Suno, Inc., No. 1:26-cv-13433. The complaint contains allegations only; no findings have been made.

Who is included in the proposed Suno class?

The complaint proposes a Nationwide Class of people in the United States whose email address or other personal information was included in the dataset obtained from Suno in connection with the November 2025 data breach, plus a California Subclass. A court has not certified either proposed class.

What claims does the Suno complaint assert?

The complaint asserts negligence, breach of implied contract, breach of the implied covenant of good faith and fair dealing, unjust enrichment and restitution, and declaratory and equitable relief.

Did Suno confirm a data breach?

TechCrunch reported on July 21, 2026 that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the reported number of affected users. Have I Been Pwned separately lists the incident as the Suno data breach.

How many Suno users may be affected?

Have I Been Pwned lists 55.3 million unique email addresses. That figure describes unique addresses in the dataset; it should not be read as 55.3 million paying customers or as proof that every listed person had every data category exposed.

What information was reportedly exposed?

The reported categories include email addresses, phone numbers used for sign-up, and tens of thousands of Stripe records containing names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of a card. The information associated with a particular person may vary.

Were Suno passwords exposed?

Have I Been Pwned does not list passwords among the compromised data categories for this incident. Users should still use a unique password, change any reused password, and enable two-factor authentication where available.

Were full credit card numbers exposed?

The public reports describe partial card data—not full card numbers—including card type, expiration date, and the last four digits. Have I Been Pwned reports that Suno said it does not have access to customers' full credit card numbers in Stripe.

Did Suno notify affected users?

TechCrunch reported that Suno had not notified customers about the November 2025 incident and, as of July 21, did not provide the outlet with a copy of any user communication when asked. Whether any person received a separate notice remains an issue under investigation.

What should I do after the Suno breach?

Use a unique password, enable two-factor authentication where available, monitor the payment card used with Suno, watch for targeted phishing, access Suno through a known official address, and preserve relevant account, purchase, and security records.

Attorney Advertising

Hall Attorneys is not affiliated with Suno, Stripe, or Have I Been Pwned. The complaint contains allegations only; no findings have been made. Sending information does not create an attorney-client relationship. Do not send passwords, authentication codes, complete card numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.