# 78 Million Accounts. Two Platforms. One Very Bad Week for the Creator Economy.


The numbers landed Monday morning like a gut punch: 55.3 million Suno accounts. 23.3 million Paidwork accounts. Have I Been Pwned confirmed both datasets, and the nature of what was taken puts these well above the routine credential-dump tier.


These aren't the same story wearing different clothes. They're two separate breach timelines, two different attacker profiles, and two communities of users who are now exposed in ways that will follow them for years.


## What Actually Got Taken


Start with Suno, the AI music generation platform that exploded in popularity over the last couple of years. The intrusion happened in November 2025 — eight months ago. The company apparently didn't notify users publicly until 404 Media forced the issue this month by reporting that attackers had walked out with source code *and* user data.


Troy Hunt's HIBP analysis pinned the unique email count at 55.3 million. But the more consequential exposure is the payment data: tens of thousands of Stripe records including names, physical addresses, purchase amounts, card type, expiration dates, and last four digits. That's not enough to clone a card — but it's more than enough to make phishing attempts surgically credible. "Your Suno subscription was charged $12.99 on March 4th" is an opener that bypasses most people's skepticism.


Then there's Paidwork. This one is worse.


The gig platform was hit in March 2026. Last week, a threat actor dropped an 11 GB database. HIBP found 23.3 million unique email addresses in the dump — but the field list is what should command attention: names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, and financial transaction history.


Bank account numbers. Not partial card data. Not a token. Actual account numbers, in a dataset now circulating freely.


## The Eight-Month Gap Nobody's Talking About


Suno's breach occurred in November 2025. The user community is finding out in July 2026.


That's not a disclosure gap — that's a disclosure canyon. Eight months is enough time for attackers to monetize, sell, re-sell, and retire the data before the first victim gets a notification email. Whether this happened because Suno didn't know, didn't want to know, or calculated that silence was preferable to regulatory attention is a question the company hasn't answered. SecurityWeek requested comment. So far, nothing.


The irony is that the breach revealed something Suno probably wanted kept even quieter: the stolen source code showed the company had been scraping music and podcasts from Deezer, YouTube, and Genius to train its AI. So Suno simultaneously victimized its users (whose data was stolen) and arguably the musicians and creators whose work was ingested without permission. The breach didn't just expose a security failure — it exposed a business model.


## Who's Most at Risk


For Suno users, the immediate threat vector is payment-data-assisted phishing. Anyone who paid for a Suno subscription should treat any billing-related email as potentially crafted from stolen records. Enable two-factor on the email account associated with Suno before doing anything else.


Paidwork users face a more serious structural problem. Gig platforms require financial information to process payouts — that's the nature of the model. People who complete small tasks for money need to connect their bank accounts. Those accounts are now in a criminal database. That's not a phishing risk. That's a bank fraud risk. Affected users should contact their financial institution, flag the account, and request a proactive review of recent transactions.


Both platforms: your email address is now confirmed as belonging to someone who uses AI music tools or gets paid for gig work. That profile information shapes future social engineering attempts in ways that aren't obvious right now but will become clear in six months when the targeting gets specific.


---


## HackWire Analysis


These two breaches are worth examining together because they reveal something about where attackers are focusing in 2026: the *monetization layer* of consumer internet services.


Suno and Paidwork aren't banks. They're not healthcare systems. They're not the obvious high-value targets that drive CISO nightmares. They're the kind of platforms that security teams at larger organizations might not even think about when they're reviewing third-party risk. But they sit on top of Stripe integrations, bank account data, and millions of identities — and they apparently did so without the security investment that data volume demands.


The Paidwork dataset is particularly worth flagging for fraud teams at financial institutions. Bank account numbers plus full names plus physical addresses plus transaction history is a remarkably complete package for account takeover attempts. The gig economy skews toward workers who may not have the resources or awareness to catch fraudulent activity quickly. Financial institutions with large populations of gig workers in their customer base should be running enhanced monitoring now, not waiting for affected customers to report problems.


The Suno situation fits a pattern we've seen repeatedly: AI consumer platforms scaling quickly on the strength of their product, with security investment trailing months or years behind user growth. The breach-to-disclosure window of eight months is a regulatory problem in most jurisdictions with meaningful privacy law. It's worth watching whether any enforcement action follows, because if it doesn't, the lesson the industry takes is that silence pays.


One more thing other coverage is missing: the source code theft at Suno likely means the breach was more targeted than a bulk credential scrape. Sophisticated actors who want source code are hunting for API keys, infrastructure configuration, and exploitable logic — not just email lists. The full scope of what was extracted may not be known yet.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)