Have I Been Pwned lists 55,282,226 unique email addresses in Suno's November 2025 breach, not 55.3 million identical customer records. The distinction is easy to lose once a rounded headline starts circulating. One number describes the size of an email-address set, while the information attached to individual records was not uniform.
Some records carried little beyond account contact information. Phone numbers appeared where they had been used as the sign-up method, while a much smaller slice of the breach involved Stripe purchase records containing names, physical addresses, purchase amounts and partial card details. Public breach listings do not name passwords as an exposed data class, and Suno has said it does not have customers' full card numbers in Stripe.
Suno has separately said more than 100 million people have tried its service. Dividing 55.3 million by that larger figure may look like a quick way to estimate what share of users were exposed, but the units do not match cleanly. One figure counts unique email addresses in a specific leaked dataset, and the other is a broader cumulative usage claim made at a different point in time.
The same problem appears when coverage calls all 55.3 million entries "customers." Suno had free users as well as paying subscribers, and the presence of only tens of thousands of Stripe purchase records makes it especially risky to read the headline number as 55.3 million paying accounts. The breach corpus was broad, but its payment-linked layer was comparatively narrow.
This is also why the Suno breach litigation affecting millions of users should not be read as proof that every proposed class member lost the same fields. The lawsuits concern exposure and alleged handling of personal information, while the public dataset description shows several different categories of information sitting inside the larger corpus.
Partial card information is still partial. The last four digits and an expiration date cannot simply be treated as a leaked payment credential capable of authorizing an ordinary card transaction, and public descriptions of the Suno breach do not list full card numbers or CVVs. Calling the entire dataset a leak of "credit card numbers" therefore overstates what is currently documented.
Risk also changes with the mix of fields attached to a person. Individual breach outcomes vary with the type of information exposed, so a single count cannot tell you whether a particular Suno record contained only an email address or a richer combination of contact, address, and purchase information. The data categories matter more once you move from describing the incident to describing an individual's exposure.
Full payment-card numbers deserve the same restraint. Public descriptions say the purchase subset contained card type, expiration date, and the last four digits, while Suno said it lacked access to full card numbers through Stripe. A headline that compresses those fields into "payment data" is technically broad enough, yet it can leave readers imagining a more complete financial record than the evidence supports.
If your address appears in the breach, the 55.3 million total alone cannot tell you which other fields were attached to your record. A free user represented by an email address, a phone-signup record, and a Stripe customer with address and purchase metadata can all sit inside the same breach while carrying very different amounts of exposed information. Public descriptions still do not provide a per-person map showing exactly which fields were taken for every affected account.
Some records carried little beyond account contact information. Phone numbers appeared where they had been used as the sign-up method, while a much smaller slice of the breach involved Stripe purchase records containing names, physical addresses, purchase amounts and partial card details. Public breach listings do not name passwords as an exposed data class, and Suno has said it does not have customers' full card numbers in Stripe.
Suno has separately said more than 100 million people have tried its service. Dividing 55.3 million by that larger figure may look like a quick way to estimate what share of users were exposed, but the units do not match cleanly. One figure counts unique email addresses in a specific leaked dataset, and the other is a broader cumulative usage claim made at a different point in time.
The headline count is an email-address count
Have I Been Pwned uses unique email addresses as the central count for this breach. An email address is useful for identifying a record, but it is not the same thing as a verified person. One person can control several addresses, and an address can exist in a service database without proving whether its owner was free, paid, active, or dormant when the incident happened.The same problem appears when coverage calls all 55.3 million entries "customers." Suno had free users as well as paying subscribers, and the presence of only tens of thousands of Stripe purchase records makes it especially risky to read the headline number as 55.3 million paying accounts. The breach corpus was broad, but its payment-linked layer was comparatively narrow.
This is also why the Suno breach litigation affecting millions of users should not be read as proof that every proposed class member lost the same fields. The lawsuits concern exposure and alleged handling of personal information, while the public dataset description shows several different categories of information sitting inside the larger corpus.
The Stripe records carry a different level of detail
The Stripe portion is where the record structure changes. Reports describing the verified dataset say tens of thousands of purchase records included names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of cards. Those fields can make a record far more specific than an email address alone, even without a full card number.Partial card information is still partial. The last four digits and an expiration date cannot simply be treated as a leaked payment credential capable of authorizing an ordinary card transaction, and public descriptions of the Suno breach do not list full card numbers or CVVs. Calling the entire dataset a leak of "credit card numbers" therefore overstates what is currently documented.
Risk also changes with the mix of fields attached to a person. Individual breach outcomes vary with the type of information exposed, so a single count cannot tell you whether a particular Suno record contained only an email address or a richer combination of contact, address, and purchase information. The data categories matter more once you move from describing the incident to describing an individual's exposure.
Missing fields matter as much as exposed ones
Passwords are not among the compromised data classes listed for the Suno incident by the public breach databases reviewed here. Its absence does not make the incident trivial, but it changes the claim you can responsibly make. The currently documented corpus does not support saying that 55.3 million Suno passwords were stolen.Full payment-card numbers deserve the same restraint. Public descriptions say the purchase subset contained card type, expiration date, and the last four digits, while Suno said it lacked access to full card numbers through Stripe. A headline that compresses those fields into "payment data" is technically broad enough, yet it can leave readers imagining a more complete financial record than the evidence supports.
If your address appears in the breach, the 55.3 million total alone cannot tell you which other fields were attached to your record. A free user represented by an email address, a phone-signup record, and a Stripe customer with address and purchase metadata can all sit inside the same breach while carrying very different amounts of exposed information. Public descriptions still do not provide a per-person map showing exactly which fields were taken for every affected account.