Overview
- A hacker using the name ellie.191 made internal Suno source code and ingestion logs public in mid‑July after a supply‑chain breach first identified in November 2025.
- The leaked files include detailed ingestion tallies such as a file listing 2,013,545 YouTube Music clips and comments noting about 113,879 hours of YouTube Music plus thousands of hours from Deezer, Genius and Pond5.
- The code shows how Suno automated scraping by routing requests through third‑party proxies, targeting a cappella tracks to isolate vocals, and using PodcastIndex to identify roughly 420,000 podcasts for possible ingestion.
- The intruder says customer contact lists and Stripe‑related metadata were accessed, while Suno says the exposed material is outdated source code, that the November incident was limited, and that full credit card numbers were not exposed.
- The leak supplies platform‑level evidence that plaintiffs and the RIAA are using in ongoing copyright suits and could push courts, regulators, and the industry toward clearer rules on licensing, data provenance, and breach disclosure.