A cyberattack on AI music generator Suno allowed a hacker to steal the personal information of more than 55.3 million people, according to the breach notification service Have I Been Pwned. The incident happened last year; word arrived roughly eight months later.
The interval is what matters. Through those months, anyone whose data was exposed had no reason to change a password, watch for fraudulent charges, or distrust a message that quoted accurate details about their own account. The window in which a victim could have acted closed before the notice.
It's worth noting where the information came from: the alert became widely known through a public checking service rather than through direct communication from the company to each affected person.
In the same week, research put the average cost of a data breach in 2026 at $4.99 million, with AI-assisted attacks running higher than average. An IBM study indicated that one in four malicious breaches now involves AI assistance.
Put those numbers beside the Suno case and the real problem comes into focus: cost is rising, detection isn't keeping pace, and the gap between attack and disclosure is still measured in months.
