Suno is facing another proposed class action over its 2025 data breach, adding a consumer-privacy fight to the legal pressure surrounding one of generative music’s largest platforms.
Michael Beckham, a Suno user from South Dakota, filed the complaint September 3rd in the U.S. District Court for the District of Massachusetts. The lawsuit alleges that the November 2025 security incident exposed personal information connected to a dataset containing approximately 55.3 million unique email addresses.
That number comes from breach-monitoring service Have I Been Pwned rather than a figure independently confirmed by Suno. Its breach database lists 55.3 million unique email addresses, while Suno has characterized the incident as limited and primarily involving outdated source code and a smaller amount of user information.
Beckham’s case is not the first lawsuit over the incident. Two earlier proposed class actions were consolidated in August, making the latest filing another front in a dispute now centered on what information was exposed, whether Suno’s security and notification practices were adequate and whether users can pursue those claims together in court.
The Breach Dates Back to November 2025
The underlying security incident happened months before its broader scale became public.
Suno says it experienced and quickly contained a security incident in November 2025. More information emerged in July, when reporting about stolen company data was followed by Have I Been Pwned adding the dataset to its breach database.
Have I Been Pwned lists approximately 55.3 million unique email addresses. Phone numbers were reportedly present for some users, while tens of thousands of Stripe purchase records included information such as names, physical addresses, purchase amounts and partial payment-card data.
Full card numbers were not included in those records. Mozilla Monitor lists partial card information, phone numbers, email addresses, physical addresses, names and purchase data among the exposed fields based on breach information from Have I Been Pwned. Passwords are not listed among the compromised data.
Suno disputes broader characterizations of the incident. Responding to earlier litigation, a company spokesperson said the event primarily involved outdated source code that was no longer being used and a limited amount of information associated with certain users. Suno has also said it does not store complete payment-card numbers or bank-account details.
The existence of a November security incident is acknowledged. What remains disputed is its significance, the adequacy of Suno’s safeguards and what the company was legally required to tell users afterward.
Beckham Says His Gmail Address Was in the Data
The newest plaintiff ties his claim directly to the compromised dataset.
Beckham says he created a Suno account using his Gmail address no later than summer 2024. According to the complaint, Have I Been Pwned later identified that address as appearing in the stolen Suno data.
The federal docket confirms that Beckham v. Suno, Inc., case No. 1:26-cv-14065, was filed September 3rd and assigned to U.S. District Judge Allison D. Burroughs.
Beckham alleges that he has spent about 10 hours responding to the breach and has experienced increased unsolicited calls and phishing attempts since the incident. Those are allegations in the complaint, not findings by the court.
His lawsuit brings claims including negligence, breach of implied contract, breach of the implied covenant of good faith and fair dealing and unjust enrichment, while also seeking declaratory and equitable relief.
The proposed nationwide class would cover U.S. users whose email addresses or other personal information appeared in the dataset obtained from Suno. Beckham also proposes a South Dakota subclass.
Requested relief includes damages, individualized information about affected data, at least five years of identity-theft and phishing protection and changes to Suno’s security practices, MBW details.
Two Earlier Suno Cases Were Already Consolidated
Federal court proceedings over the breach were already underway before Beckham filed his complaint.
Judge Burroughs consolidated two earlier cases on August 24th. Pilavian v. Suno, Inc. became the lead case, while Rugnetta v. Suno, Inc. was designated the member case and administratively closed.
Digital Music News documented the consolidation after both proposed class actions accused Suno of negligence and other failures connected to the November incident.
The court gave the plaintiffs 30 days from the August 24th order to submit a consolidated complaint. Suno then receives 45 days to respond, while previous response deadlines in the individual cases were stayed.
Beckham identifies his lawsuit as related to Pilavian, leaving open the possibility of coordinated proceedings or another consolidation decision.
No court has determined that Suno violated data-security or consumer-protection law. The complaints contain allegations that will have to survive procedural challenges and, if the litigation continues, be tested against Suno’s defenses and evidence.
Arbitration Could Become a Major Fight
One of the more consequential parts of Beckham’s complaint concerns the terms users accept when they create or use an online account.
The filing anticipates that Suno may attempt to invoke an arbitration agreement, class-action waiver, delegation clause, limitation period or liability cap contained in its terms.
Beckham does not concede that those provisions are enforceable against him.
Instead, the complaint challenges whether Suno provided sufficiently conspicuous notice for a user to form a valid agreement to arbitrate disputes. That question could become important before the court reaches some of the underlying data-security allegations.
If an arbitration provision applies, users may be required to pursue individual claims outside court rather than participate in a class action. If the provision is found unenforceable or the court concludes that no valid agreement was formed, the proposed class litigation has a clearer path forward.
The issue extends beyond Suno. Subscription apps and digital platforms routinely incorporate contractual terms through account creation, checkout screens or links to broader terms of service rather than traditional signed agreements.
Beckham’s complaint specifically challenges whether the notice surrounding Suno’s provisions was sufficient. Whether the court agrees remains unresolved.
Suno Says the Incident Was Limited
Suno’s public description of the breach is considerably narrower than the allegations in the lawsuits.
When the first proposed data-breach actions appeared in July, a company spokesperson said Suno takes user information seriously and had hired an outside cybersecurity expert to audit its findings.
Suno characterized the November event as a quickly contained security incident that primarily involved outdated source code no longer in use.
The company also concluded that individualized breach notifications were not required under applicable privacy laws, according to its earlier statements.
That decision is now part of the dispute.
Beckham alleges that Suno did not provide him with information identifying exactly which fields associated with his account were accessed or taken. He argues that the lack of individualized information prevented him from taking more targeted protective measures.
Suno’s privacy notice acknowledges that no security system can guarantee perfect protection while stating that the company uses commercially reasonable safeguards. The lawsuit challenges whether those safeguards and Suno’s response to the incident were sufficient.
The Case Opens Another Front for Suno
Data privacy is joining copyright and artist-rights disputes on Suno’s growing legal docket.
The company’s better-known music cases concern the material used to train earlier generations of its AI models and the rights attached to recordings, compositions and artist identities. The breach litigation asks a different question: how Suno protected information belonging to people using its platform.
Scale makes that distinction increasingly important. Suno co-founder and CEO Mikey Shulman has said more than 100 million people have used the service, while the company raised more than $400 million in June at a reported $5.4 billion valuation, MBW notes.
Email addresses, phone numbers and purchase information have little to do with whether an AI-generated song sounds convincing, but they become part of the same company’s responsibilities once a music tool grows into a consumer platform serving tens of millions of accounts.
The privacy cases also arrive while Suno is pursuing more conventional relationships with the music industry through licensed models and commercial partnerships. Consumer trust now sits beside licensing and copyright as another issue the company has to manage.
55.3 Million Emails Does Not Mean 55.3 Million Victims
The headline number deserves careful handling.
Have I Been Pwned lists approximately 55.3 million unique email addresses associated with the Suno dataset. That establishes the scale of the data analyzed by the breach-monitoring service, but it is not the same as a judicial finding that 55.3 million individual people suffered legally compensable harm.
Different accounts may also have different combinations of information associated with them. The litigation has not established what happened to every person represented in the dataset.
The same caution applies to downstream harm. Beckham alleges increased spam and phishing attempts and says he spent hours protecting himself after learning of the breach. The court has not determined whether those alleged injuries were caused by the Suno incident or whether they support damages across a proposed class.
Have I Been Pwned records a Suno breach containing 55.3 million unique email addresses. Suno acknowledges a November 2025 security incident, and multiple proposed class actions are now moving through federal court over how the company handled it.
Beckham’s September 3rd complaint adds another question to that litigation: whether Suno’s own online terms can keep those claims out of a class-action courtroom.