Two large-scale data breaches surfaced this week, collectively exposing the personal and financial data of over 78 million users. AI music generation platform Suno had 55.3 million accounts added to Have I Been Pwned (HIBP) following a November 2025 breach via the Shai-Hulud npm supply-chain worm. Simultaneously, gig-work microtask platform Paidwork confirmed a 23-million-account breach that exposed banking details, transaction histories, and home addresses — data first advertised on cybercrime forums in April 2026 before being posted publicly in July.
Suno: 55.3 Million Accounts via Supply-Chain Worm
What Happened
In November 2025, a threat actor operating under the handle ellie.191 leveraged the Shai-Hulud npm supply-chain worm to compromise credentials belonging to a Suno developer. The worm — first identified by Palo Alto Unit 42 in September 2025 — infected the developer's build pipeline, harvested GitHub tokens and cloud credentials, and used that access to reach Suno's private code repositories and internal databases.
Suno internally characterized the event as a "limited security incident" involving "outdated source code" and did not notify users at the time. The true scope became public on July 20, 2026, when HIBP added 55,282,226 unique email addresses from the breach.
What Was Exposed
| Data Type | Scope |
|---|---|
| Email addresses | 55.3 million unique |
| Phone numbers | Included in exposed dataset |
| Stripe payment records | Tens of thousands (names, addresses, purchase amounts, card type, expiry, last 4 digits) |
| Source code | Private repositories accessed and downloaded |
The payment record exposure is particularly serious — while full card numbers were not included, the combination of name, billing address, card type, expiry, and last four digits is frequently sufficient for social engineering attacks against financial institutions and for card-not-present fraud enablement.
The Shai-Hulud Worm
Shai-Hulud is a self-replicating npm supply-chain worm with a notably aggressive propagation mechanism:
- Infection — Targets developer build pipelines through malicious or hijacked npm packages
- Credential harvesting — Runs a weaponized version of TruffleHog to scan for GitHub tokens and cloud credentials
- Exfiltration — Publishes stolen secrets to public GitHub repositories under the victim's own account
- Propagation — Uses stolen npm tokens to backdoor and republish legitimate packages, spreading exponentially without direct attacker intervention
The worm's self-replicating nature means a single compromised developer account can cascade through an entire ecosystem of packages and organizations that depend on them — without the original attacker needing to touch each downstream victim.
Leaked Source Code Implications
Beyond the breach itself, the leaked Suno source code revealed that the platform had scraped training data from YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and podcast RSS feeds — evidence directly relevant to ongoing copyright litigation against Suno from UMG and Sony. The breach effectively surfaced evidence that could accelerate legal proceedings against the company.
Paidwork: 23 Million Accounts with Banking Data
What Happened
Paidwork, a gig-economy microtask platform, was breached in March 2026. An 11 GB database was first advertised on a cybercrime forum in April 2026, then posted publicly in July 2026 — confirming the full scope of the breach and making the data freely available to any threat actor.
What Was Exposed
The Paidwork breach stands out for the depth of personal and financial data included:
| Category | Data Fields |
|---|---|
| Identity | Full names, email addresses, dates of birth, gender |
| Contact | Home addresses, phone numbers |
| Financial | Bank account numbers, transaction records |
| Device | Device identifiers, IP addresses |
| Profile | Profile photos, personal interests, education details |
| Security | Hashed passwords |
Bank account numbers and transaction histories in the dataset make this breach particularly dangerous for direct financial fraud. The combination of home addresses, phone numbers, dates of birth, and financial data creates an exceptionally complete profile for identity theft and social engineering.
Why This Breach Is Especially Dangerous
Unlike breaches that expose email addresses and hashed passwords alone, the Paidwork dataset:
- Enables direct financial fraud — Bank account numbers and transaction records can be used to initiate unauthorized transfers or as verification data with financial institutions
- Supports precise social engineering — Full profiles with physical addresses, phone numbers, and financial data allow threat actors to impersonate victims convincingly
- Facilitates credential stuffing — Even hashed passwords, if cracked, enable account takeover across platforms where users reuse passwords
- Provides physical attack vectors — Home addresses in combination with financial data can support physical fraud, mail interception, or targeted theft
What Affected Users Should Do
If you have accounts on either platform, take these steps immediately:
If you used Suno:
- Check if your email was exposed at haveibeenpwned.com
- Monitor linked payment methods and Stripe-connected accounts for unauthorized charges
- Change your Suno password and any reused passwords on other platforms
- Be alert to phishing emails using your Suno account details as social engineering bait
If you used Paidwork:
- Contact your bank to review recent transactions and consider flagging your account for fraud monitoring
- Consider placing a fraud alert or credit freeze with credit bureaus if you are in a jurisdiction where this applies
- Change passwords on Paidwork and anywhere you reused that password
- Be alert to vishing (phone-based phishing) calls using your personal details — attackers with your address and financial data are well-equipped to impersonate institutions
The Broader Pattern
Both breaches reflect systemic issues in how platforms handle security incidents:
- Suno's delayed disclosure — The November 2025 breach was not disclosed to users until HIBP added records in July 2026, an eight-month gap that left tens of millions of users unable to protect themselves
- Paidwork's forum advertisement — The three-month window between the cybercrime forum listing (April) and public disclosure (July) represents another period where threat actors had exclusive access to the data before victims were aware
Regulators in the EU (under GDPR's 72-hour breach notification requirement) and elsewhere are increasingly scrutinizing delayed disclosures as a compliance violation in its own right.
References
- Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts — SecurityWeek
- AI music platform Suno hits bum note as 55M users exposed — The Register
- Suno Breached via Shai-Hulud Worm — Socket.dev
- Paidwork breach exposes data of 23 million users — Malwarebytes
- Paidwork breach exposes sensitive data of 23 million users — Help Net Security
- "Shai-Hulud" Worm Compromises npm Ecosystem — Palo Alto Unit 42