← Back to Explainers
LEAKLENS EXPLAINER · 2026-07-23

Two Breaches, One Week, Two Ways of Staying Silent: Paidwork, Suno, and 78 Million Exposed Accounts

LEAKLENS EXPLAINER · JULY 2026

# Two Breaches, One Week, Two Ways of Not Telling Users: Paidwork, Suno, and 78 Million Exposed Accounts

What happened at each company, what leaked, and what "confirming a breach" actually meant in practice for the people affected


23,272,765 — Paidwork accounts confirmed by HaveIBeenPwned 55,300,000 — Suno accounts confirmed by HaveIBeenPwned ~78.6 million — combined confirmed accounts across both breaches 0 — users directly notified by either company, as far as public reporting shows
Editorial note: these are two unrelated companies, breached by different attackers for different reasons, discovered independently. We're covering them together because HaveIBeenPwned added both to its database within a day of each other (July 19–20, 2026), and because how each company handled disclosure afterward makes an instructive pair: total silence from Paidwork, and a statement from Suno that's on the record but doesn't fully match what independent analysis of the leaked data shows. Nothing here should be read as implying the two incidents are connected.

The short version

In the same week, HaveIBeenPwned confirmed two large, unrelated breaches: one at Paidwork, a microtask gig-work app, and one at Suno, an AI music generator currently being sued by major record labels. Together they cover close to 80 million accounts.

Neither company has notified users directly. Paidwork hasn't said anything publicly at all. Suno has — twice, in fact — but what it told reporters doesn't line up cleanly with what independent analysis of the leaked data actually shows, and its explanation for not notifying users turns out to be a specific legal argument, not just silence.


Part 1: What happened at each company

Paidwork: the silent one

Paidwork pays users small amounts — a few cents at a time — for tasks like watching ads, testing apps, and filling out surveys. The breach exposed far more than the low-stakes sign-up implies.

What happened: An intrusion reportedly occurred in March 2026. In April, a threat actor using the alias "hackformetome" advertised an 11GB database dump on a cybercrime forum, claiming records on 22+ million users — a claim at least one security tracker rated as unconfirmed at the time. HaveIBeenPwned added the breach to its database on July 19, confirming 23,272,765 accounts. What was exposed: Full names, email and home addresses, phone numbers, dates of birth, gender, education level, bank account numbers, transaction records, device and IP data, profile photos, personal interests, and passwords stored as bcrypt hashes. Company response: None, publicly. Help Net Security and The Register both reported that Paidwork had not acknowledged the incident as of July 20. SecurityWeek says it reached out to Paidwork for comment and had not received a response as of its July 22 report. (A plaintiff-side law firm, Hall Attorneys, is separately soliciting potential litigation clients over the breach — worth knowing if you encounter that page, since it's not an independent news source, even though its facts line up with the outlets above.)

Suno: the disputed one

Suno is one of the biggest AI music generators on the internet — type in a prompt, get a full song back. It's also been fighting the recording industry in court since 2024 over allegations that it trained its models on copyrighted music without permission.

Timeline: (Marginal note: it's not established whether ellie.191 planted the original Shai-Hulud infection or simply found credentials the worm had already exposed — Shai-Hulud is known to dump what it steals into a public GitHub repo under the victim's own account, meaning the access may have simply been sitting out in the open.) How the breach happened: This wasn't a direct attack on Suno's servers. It started with Shai-Hulud, a self-replicating worm that spreads through trojanized npm packages and steals GitHub and cloud credentials from developer machines and CI pipelines. Compromising a single Suno employee's machine was reportedly enough to give the attacker a path to the company's private source code and cloud-hosted customer data. What was exposed: Email addresses and phone numbers for the broader user base, plus tens of thousands of Stripe payment records — customer names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of payment cards. Separately, the same leak included internal source code logging exactly what Suno's models were trained on: leaked files reportedly show Suno ingested over 2 million clips from YouTube Music alone, plus large volumes from Deezer, Genius, Pond5, Jamendo, and other platforms — reportedly routed through proxy infrastructure to scrape YouTube specifically. This is why the story is getting attention well outside the security world: record labels UMG and Sony are currently suing Suno and pushing to expand the case from 560 works to over 61,000, based on audio fingerprinting of Suno's training data.

Part 2: What each company actually said — and what that means

When people talk about a company "confirming" a data breach, they usually picture something like a press release, a notification email, or a banner on the login page. In practice, that's not what confirmation looks like — and comparing what Paidwork and Suno actually did shows why that gap matters.

Paidwork: total silence

As of this writing, there is no statement from Paidwork anywhere — not on its website, not in a press release, not in response to press inquiries. This is the simpler case: whatever legal or PR reasoning is behind it, users have no company-provided information to go on. Only the independent analysis from HaveIBeenPwned and the security outlets who reviewed the leaked dataset fills that gap.

Suno: on the record, twice, and still not enough

Suno's case is more instructive, because on the surface it looks like the opposite of Paidwork's: the company did respond — twice, six days apart.

First, to 404 Media and Engadget, in a statement attributed only to "a Suno spokesperson":

"In November of 2025, we determined that Suno had been the subject of a limited security incident that was quickly contained. At the time, we immediately conducted an investigation and verified that the incident primarily involved outdated source code that is no longer in use at Suno and that no sensitive personal information was compromised. Importantly, Suno does not have access to customers' full credit card numbers in Stripe."

Read closely, this statement does several things at once:

That same statement directly addressed why no one got a notification email: Suno said it had concluded individual breach notifications "were not warranted under applicable privacy laws" — a specific legal justification, not just silence. It separately noted it had filed a California-mandated disclosure about its AI training data, a different legal requirement, unrelated to the breach itself.

Six days later, once HaveIBeenPwned's confirmed numbers made the story bigger, TechCrunch pressed further and got Suno spokesperson Rachel Racusen on the record by name — she did not dispute the 55.3 million figure and confirmed the November 2025 incident.

The nuance worth sitting with

Paidwork's silence is unexplained. Suno's silence toward users specifically was a deliberate legal judgment call, stated on the record. That's a meaningful difference in intent — but not in outcome. Neither the "say nothing" approach nor the "explain to reporters why individual notice wasn't required" approach results in the person whose bank details, address, or phone number was exposed getting a direct heads-up. In both cases, that person's best source of truth is a third party — HaveIBeenPwned — not the company that held their data.

That's the actual reason breach-checking tools exist, worth stating plainly: company statements, when they exist at all, are written for reporters and, eventually, regulators and plaintiffs' attorneys — not as a substitute for checking your own exposure directly.


What the two breaches have in common

What to do, either way

  • Change your password on the affected service, and anywhere you reused it.
  • Enable two-factor authentication wherever it's offered.
  • Watch your bank and card statements closely for the next few months — stolen financial data tends to surface in fraud slowly, not all at once.
  • Be suspicious of messages referencing real account activity — a scammer with your real purchase history, payout amount, or address can make a phishing attempt look far more convincing than a generic one.
  • Check your exposure at HaveIBeenPwned for either service — don't wait for an email that, based on how both companies have handled this so far, may never come.
  • If you're a musician or rights holder concerned about the AI-training angle of the Suno leak, that's a separate legal question from the data breach itself, tied to the ongoing UMG/Sony litigation — outside the scope of the practical steps above.

  • Sources:

    Open items before publication

  • The exact "2,013,545 YouTube Music clips" figure is sourced to 404 Media's original reporting; several outlets have since repeated it, but none appear to have independently re-verified it against the leaked files themselves. Treat it as single-sourced.
  • It's unconfirmed whether ellie.191 caused the original Shai-Hulud infection or discovered already-exposed credentials — see the marginal note above.
  • Neither company had issued a further statement, notified users directly, or faced a confirmed regulatory action as of July 23, 2026. This piece should be revisited if that changes.