Leaked Suno code shows it scraped 2M+ YouTube songs for AI training
Curated by the Inblix editorial team
The black box around Suno’s training data just cracked open. Files obtained by 404 Media through a hack reveal the AI music generator systematically scraped over two million tracks from YouTube Music, alongside thousands of hours of audio from Deezer, Genius, and other platforms. The leaked source code from 2023 and 2024 doesn’t just list targets — it includes scraping instructions and references to Bright Data, a third-party service apparently used to pull audio from YouTube. One file even suggests Suno specifically hunted for a cappella tracks, an effort to isolate clean vocal samples.
This lands squarely in the middle of the RIAA’s ongoing copyright lawsuit, where Suno has already admitted to training on copyrighted materials while claiming fair use protection. The RIAA amended its complaint last year to allege that Suno intentionally circumvented YouTube’s copyright protections by stream-ripping content. The leaked materials appear to corroborate that accusation, detailing consumption of roughly one million hours of podcasts through PodcastIndex alongside the music scraping operation. Suno’s response has been consistent: a spokesperson told 404 Media that its models were trained on “publicly available music files and related metadata accessible on third-party websites on the open Internet.”
Beyond the training data, the breach exposed customer information — email addresses, phone numbers, and Stripe payment details. Several users confirmed to 404 Media that they never received a breach notification. Suno claims the November 2025 security incident was quickly contained and involved “outdated source code that is no longer in use,” adding that no sensitive personal information was compromised and that individual notifications weren’t warranted under applicable privacy laws. That explanation will likely raise eyebrows among security professionals who generally favor more transparency.
The scope is staggering when you look at the numbers. Beyond the 2,013,545 YouTube Music clips, Suno’s datasets encompassed hundreds of thousands of hours from YouTube broadly, thousands of hours each from Deezer, Genius, and Jamendo, and hundreds of hours from Freesound and MuseScore lyrics. The inclusion of IMSLP — the International Music Score Library Project — suggests Suno was ingesting classical compositions and sheet music too, likely for structural training. The question courts will eventually answer isn’t whether Suno scraped at scale — that much is now undeniable — but whether doing so constitutes the kind of transformative use that fair use doctrine was designed to protect.
💡 Key Takeaways
- Suno scraped over 2 million YouTube Music clips and hundreds of thousands of hours from other platforms, according to leaked source code and scraping instructions obtained by a hacker.
- The leaked data backs up the RIAA's allegation that Suno used third-party services like Bright Data to stream-rip copyrighted content from YouTube, including targeted searches for isolated vocal tracks.
- Suno did not notify customers about the November 2025 breach that exposed email addresses, phone numbers, and Stripe payment details, claiming individual notifications weren't legally required.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.