AI music generator Suno has confirmed it was hacked, in a breach that exposed user information and internal source code — and that source code reportedly lays bare how the company built its training data.

According to Engadget, Suno says the breach happened in November and that "no sensitive personal information was compromised." That reassurance, however, is not the part drawing attention.

According to TechCrunch, the hacker used an employee's credentials to reach Suno's source code, which revealed how the company scraped decades of audio. TechCrunch reports the code suggests Suno pulled training material from YouTube.

The most detailed account comes from Jason Koebler at 404 Media, surfaced via Techmeme. Koebler reports that a hacker claims to have accessed Suno user info and source code showing how the company scraped music, and that the hacked code reveals how Suno gathered decades' worth of music and podcasts from across the internet to train its models. Suno, for its part, maintains that no sensitive information was compromised in the November incident.

Engadget adds that the source code reportedly details how the company scraped millions of songs.

The breach matters on two fronts. First, it is a security failure: an employee's credentials were enough to open the door to internal code. Second, and more explosively, the leaked code offers an unusually direct look at a question at the heart of AI's legal fights — where generative music systems get their training data. AI companies are already facing lawsuits over unlicensed use of copyrighted work, and internal evidence of large-scale scraping from platforms like YouTube could reshape those disputes.

Why it matters: a hack meant to expose one company's weak security may end up exposing the AI industry's most contested secret — how these models are really trained.