Suno said it decided in November 2025 that individual breach notifications were not warranted under applicable privacy laws. The company also said its investigation found a limited incident involving mainly outdated source code and no sensitive personal information.
Public reporting changed the picture months later. In July 2026, a verified breach dataset was described as containing more than 55 million unique email addresses, phone numbers for some users, and tens of thousands of Stripe purchase records with names, physical addresses, purchase amounts, and partial card details.
Those two descriptions are uncomfortable beside each other, but they do not automatically prove a notification-law violation. The harder issue behind Suno's decision not to notify affected users is whether the specific information taken from particular residents crossed the legal notification threshold in the states whose laws applied.
Massachusetts is a useful example because Suno is based there. Its breach law defines protected personal information around a resident's name combined with specified identifiers such as a Social Security number, driver's license number, or financial account or payment-card information capable of permitting access to a financial account. An email address by itself does not satisfy that statutory definition.
The distinction matters for Suno because the publicly described dataset is uneven. More than 55 million email addresses form the broadest layer, while richer Stripe records make up a much smaller portion, and the public descriptions identify partial card details rather than complete card numbers. Knowing a breach contains names, addresses, and the last four digits of some cards does not tell you whether every affected Massachusetts record met the state's statutory trigger.
The patchwork of breach-notification triggers and enforcement rules is especially important when a dataset mixes basic contact records with smaller pockets of richer information. A company's conclusion can therefore depend on which resident is being assessed and which fields were attached to that person's record, rather than on the headline size of the breach alone.
South Dakota shows the difference clearly because Michael Beckham, the plaintiff in the newest proposed class action, is domiciled there. State law requires notice when covered personal or protected information was acquired, or is reasonably believed to have been acquired, by an unauthorized person. It generally sets a 60-day window after discovery or notification of the breach.
South Dakota also allows an information holder to avoid individual disclosure after an appropriate investigation if it reasonably determines the breach is unlikely to result in harm, with notice to the attorney general and written documentation retained for at least three years. Its protected-information definition includes an email address paired with a password, security-answer information, or something else that permits access to an online account. An exposed email address standing alone is a different case.
Timing is another separate issue. Massachusetts requires covered notices as soon as practicable and without unreasonable delay, while South Dakota generally specifies 60 days unless an exception applies. Suno knew of the security incident in November 2025, but the breach became public roughly eight months later after outside reporting and the dataset's appearance in breach-notification services.
A long gap can look damning without answering the legal trigger first. If a state's covered information was not compromised, its consumer-notice deadline may never have started under that statute. If covered information was compromised and no exception applied, the timing rules become much harder to ignore.
The strongest unresolved point is therefore not simply that Suno stayed quiet for months. It is whether Suno's November assessment matched the information later shown to exist in the stolen corpus, including the smaller set of records containing physical addresses, purchase histories and partial payment-card details. Publicly available descriptions establish the tension, but the missing per-user data and internal investigation records are what would determine where a notification duty actually attached.
Public reporting changed the picture months later. In July 2026, a verified breach dataset was described as containing more than 55 million unique email addresses, phone numbers for some users, and tens of thousands of Stripe purchase records with names, physical addresses, purchase amounts, and partial card details.
Those two descriptions are uncomfortable beside each other, but they do not automatically prove a notification-law violation. The harder issue behind Suno's decision not to notify affected users is whether the specific information taken from particular residents crossed the legal notification threshold in the states whose laws applied.
Breach-notification law uses narrower definitions
Everyday language makes this sound simple. An email address, home address, phone number, and purchase history are plainly personal information in the ordinary sense, yet breach statutes often use narrower technical definitions that determine when mandatory notice begins.Massachusetts is a useful example because Suno is based there. Its breach law defines protected personal information around a resident's name combined with specified identifiers such as a Social Security number, driver's license number, or financial account or payment-card information capable of permitting access to a financial account. An email address by itself does not satisfy that statutory definition.
The distinction matters for Suno because the publicly described dataset is uneven. More than 55 million email addresses form the broadest layer, while richer Stripe records make up a much smaller portion, and the public descriptions identify partial card details rather than complete card numbers. Knowing a breach contains names, addresses, and the last four digits of some cards does not tell you whether every affected Massachusetts record met the state's statutory trigger.
A nationwide breach creates several legal tests
Suno had users across the United States, so Massachusetts law is not the only relevant rule. State breach statutes differ over the information they protect, the level of likely harm needed to trigger notice, deadlines, regulator reporting, and circumstances that permit delayed or substitute notice.The patchwork of breach-notification triggers and enforcement rules is especially important when a dataset mixes basic contact records with smaller pockets of richer information. A company's conclusion can therefore depend on which resident is being assessed and which fields were attached to that person's record, rather than on the headline size of the breach alone.
South Dakota shows the difference clearly because Michael Beckham, the plaintiff in the newest proposed class action, is domiciled there. State law requires notice when covered personal or protected information was acquired, or is reasonably believed to have been acquired, by an unauthorized person. It generally sets a 60-day window after discovery or notification of the breach.
South Dakota also allows an information holder to avoid individual disclosure after an appropriate investigation if it reasonably determines the breach is unlikely to result in harm, with notice to the attorney general and written documentation retained for at least three years. Its protected-information definition includes an email address paired with a password, security-answer information, or something else that permits access to an online account. An exposed email address standing alone is a different case.
The missing facts decide more than the headline
The public record still lacks several facts needed to judge Suno's notification decision cleanly. We do not have a complete resident-by-resident breakdown of the stolen fields, Suno's internal legal analysis, its forensic findings at the time, or a full public record of any regulator communications made under individual state laws.Timing is another separate issue. Massachusetts requires covered notices as soon as practicable and without unreasonable delay, while South Dakota generally specifies 60 days unless an exception applies. Suno knew of the security incident in November 2025, but the breach became public roughly eight months later after outside reporting and the dataset's appearance in breach-notification services.
A long gap can look damning without answering the legal trigger first. If a state's covered information was not compromised, its consumer-notice deadline may never have started under that statute. If covered information was compromised and no exception applied, the timing rules become much harder to ignore.
The strongest unresolved point is therefore not simply that Suno stayed quiet for months. It is whether Suno's November assessment matched the information later shown to exist in the stolen corpus, including the smaller set of records containing physical addresses, purchase histories and partial payment-card details. Publicly available descriptions establish the tension, but the missing per-user data and internal investigation records are what would determine where a notification duty actually attached.