Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2011+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
NEWS

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Two major data breaches came to light this week: AI music platform Suno had 55.3 million accounts exposed after a supply-chain worm compromised developer credentials in November 2025, while gig-work platform Paidwork saw 23 million accounts — including banking details — leaked publicly from a March 2026 intrusion.

Dylan H.

News Desk

July 22, 2026
6 min read

Two large-scale data breaches surfaced this week, collectively exposing the personal and financial data of over 78 million users. AI music generation platform Suno had 55.3 million accounts added to Have I Been Pwned (HIBP) following a November 2025 breach via the Shai-Hulud npm supply-chain worm. Simultaneously, gig-work microtask platform Paidwork confirmed a 23-million-account breach that exposed banking details, transaction histories, and home addresses — data first advertised on cybercrime forums in April 2026 before being posted publicly in July.

Suno: 55.3 Million Accounts via Supply-Chain Worm

What Happened

In November 2025, a threat actor operating under the handle ellie.191 leveraged the Shai-Hulud npm supply-chain worm to compromise credentials belonging to a Suno developer. The worm — first identified by Palo Alto Unit 42 in September 2025 — infected the developer's build pipeline, harvested GitHub tokens and cloud credentials, and used that access to reach Suno's private code repositories and internal databases.

Suno internally characterized the event as a "limited security incident" involving "outdated source code" and did not notify users at the time. The true scope became public on July 20, 2026, when HIBP added 55,282,226 unique email addresses from the breach.

What Was Exposed

Data TypeScope
Email addresses55.3 million unique
Phone numbersIncluded in exposed dataset
Stripe payment recordsTens of thousands (names, addresses, purchase amounts, card type, expiry, last 4 digits)
Source codePrivate repositories accessed and downloaded

The payment record exposure is particularly serious — while full card numbers were not included, the combination of name, billing address, card type, expiry, and last four digits is frequently sufficient for social engineering attacks against financial institutions and for card-not-present fraud enablement.

The Shai-Hulud Worm

Shai-Hulud is a self-replicating npm supply-chain worm with a notably aggressive propagation mechanism:

  1. Infection — Targets developer build pipelines through malicious or hijacked npm packages
  2. Credential harvesting — Runs a weaponized version of TruffleHog to scan for GitHub tokens and cloud credentials
  3. Exfiltration — Publishes stolen secrets to public GitHub repositories under the victim's own account
  4. Propagation — Uses stolen npm tokens to backdoor and republish legitimate packages, spreading exponentially without direct attacker intervention

The worm's self-replicating nature means a single compromised developer account can cascade through an entire ecosystem of packages and organizations that depend on them — without the original attacker needing to touch each downstream victim.

Leaked Source Code Implications

Beyond the breach itself, the leaked Suno source code revealed that the platform had scraped training data from YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and podcast RSS feeds — evidence directly relevant to ongoing copyright litigation against Suno from UMG and Sony. The breach effectively surfaced evidence that could accelerate legal proceedings against the company.

Paidwork: 23 Million Accounts with Banking Data

What Happened

Paidwork, a gig-economy microtask platform, was breached in March 2026. An 11 GB database was first advertised on a cybercrime forum in April 2026, then posted publicly in July 2026 — confirming the full scope of the breach and making the data freely available to any threat actor.

What Was Exposed

The Paidwork breach stands out for the depth of personal and financial data included:

CategoryData Fields
IdentityFull names, email addresses, dates of birth, gender
ContactHome addresses, phone numbers
FinancialBank account numbers, transaction records
DeviceDevice identifiers, IP addresses
ProfileProfile photos, personal interests, education details
SecurityHashed passwords

Bank account numbers and transaction histories in the dataset make this breach particularly dangerous for direct financial fraud. The combination of home addresses, phone numbers, dates of birth, and financial data creates an exceptionally complete profile for identity theft and social engineering.

Why This Breach Is Especially Dangerous

Unlike breaches that expose email addresses and hashed passwords alone, the Paidwork dataset:

  • Enables direct financial fraud — Bank account numbers and transaction records can be used to initiate unauthorized transfers or as verification data with financial institutions
  • Supports precise social engineering — Full profiles with physical addresses, phone numbers, and financial data allow threat actors to impersonate victims convincingly
  • Facilitates credential stuffing — Even hashed passwords, if cracked, enable account takeover across platforms where users reuse passwords
  • Provides physical attack vectors — Home addresses in combination with financial data can support physical fraud, mail interception, or targeted theft

What Affected Users Should Do

If you have accounts on either platform, take these steps immediately:

If you used Suno:

  1. Check if your email was exposed at haveibeenpwned.com
  2. Monitor linked payment methods and Stripe-connected accounts for unauthorized charges
  3. Change your Suno password and any reused passwords on other platforms
  4. Be alert to phishing emails using your Suno account details as social engineering bait

If you used Paidwork:

  1. Contact your bank to review recent transactions and consider flagging your account for fraud monitoring
  2. Consider placing a fraud alert or credit freeze with credit bureaus if you are in a jurisdiction where this applies
  3. Change passwords on Paidwork and anywhere you reused that password
  4. Be alert to vishing (phone-based phishing) calls using your personal details — attackers with your address and financial data are well-equipped to impersonate institutions

The Broader Pattern

Both breaches reflect systemic issues in how platforms handle security incidents:

  • Suno's delayed disclosure — The November 2025 breach was not disclosed to users until HIBP added records in July 2026, an eight-month gap that left tens of millions of users unable to protect themselves
  • Paidwork's forum advertisement — The three-month window between the cybercrime forum listing (April) and public disclosure (July) represents another period where threat actors had exclusive access to the data before victims were aware

Regulators in the EU (under GDPR's 72-hour breach notification requirement) and elsewhere are increasingly scrutinizing delayed disclosures as a compliance violation in its own right.

References

  • Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts — SecurityWeek
  • AI music platform Suno hits bum note as 55M users exposed — The Register
  • Suno Breached via Shai-Hulud Worm — Socket.dev
  • Paidwork breach exposes data of 23 million users — Malwarebytes
  • Paidwork breach exposes sensitive data of 23 million users — Help Net Security
  • "Shai-Hulud" Worm Compromises npm Ecosystem — Palo Alto Unit 42
#Data Breach#Supply Chain#AI Platform#FinTech#npm#Have I Been Pwned

Related Articles

Grafana Says Codebase and Other Data Stolen via TanStack

Grafana confirmed attackers stole internal source code and data after a GitHub token compromised in the TanStack npm supply chain attack was never...

4 min read

GitHub Links Repo Breach to TanStack npm Supply-Chain Attack

GitHub has confirmed that hackers who stole 3,800 internal repositories gained access through a malicious version of the Nx Console VS Code extension...

6 min read

GitHub Breached — Employee Device Hack Led to Exfiltration

GitHub is investigating unauthorized access to thousands of internal repositories after an employee device was compromised through the TanStack npm supply...

6 min read
Back to all News