Two Breaches, One Week, Two Ways of Staying Silent: Paidwork, Suno, and 78 Million Exposed Accounts
LEAKLENS EXPLAINER · JULY 2026
# Two Breaches, One Week, Two Ways of Not Telling Users: Paidwork, Suno, and 78 Million Exposed Accounts
What happened at each company, what leaked, and what "confirming a breach" actually meant in practice for the people affected
23,272,765 — Paidwork accounts confirmed by HaveIBeenPwned 55,300,000 — Suno accounts confirmed by HaveIBeenPwned ~78.6 million — combined confirmed accounts across both breaches 0 — users directly notified by either company, as far as public reporting shows
Editorial note: these are two unrelated companies, breached by different attackers for different reasons, discovered independently. We're covering them together because HaveIBeenPwned added both to its database within a day of each other (July 19–20, 2026), and because how each company handled disclosure afterward makes an instructive pair: total silence from Paidwork, and a statement from Suno that's on the record but doesn't fully match what independent analysis of the leaked data shows. Nothing here should be read as implying the two incidents are connected.
The short version
In the same week, HaveIBeenPwned confirmed two large, unrelated breaches: one at Paidwork, a microtask gig-work app, and one at Suno, an AI music generator currently being sued by major record labels. Together they cover close to 80 million accounts.
Neither company has notified users directly. Paidwork hasn't said anything publicly at all. Suno has — twice, in fact — but what it told reporters doesn't line up cleanly with what independent analysis of the leaked data actually shows, and its explanation for not notifying users turns out to be a specific legal argument, not just silence.
Part 1: What happened at each company
Paidwork: the silent one
Paidwork pays users small amounts — a few cents at a time — for tasks like watching ads, testing apps, and filling out surveys. The breach exposed far more than the low-stakes sign-up implies.
What happened: An intrusion reportedly occurred in March 2026. In April, a threat actor using the alias "hackformetome" advertised an 11GB database dump on a cybercrime forum, claiming records on 22+ million users — a claim at least one security tracker rated as unconfirmed at the time. HaveIBeenPwned added the breach to its database on July 19, confirming 23,272,765 accounts. What was exposed: Full names, email and home addresses, phone numbers, dates of birth, gender, education level, bank account numbers, transaction records, device and IP data, profile photos, personal interests, and passwords stored as bcrypt hashes. Company response: None, publicly. Help Net Security and The Register both reported that Paidwork had not acknowledged the incident as of July 20. SecurityWeek says it reached out to Paidwork for comment and had not received a response as of its July 22 report. (A plaintiff-side law firm, Hall Attorneys, is separately soliciting potential litigation clients over the breach — worth knowing if you encounter that page, since it's not an independent news source, even though its facts line up with the outlets above.)Suno: the disputed one
Suno is one of the biggest AI music generators on the internet — type in a prompt, get a full song back. It's also been fighting the recording industry in court since 2024 over allegations that it trained its models on copyrighted music without permission.
Timeline:- September 2025 — Palo Alto Networks' Unit 42 first documents "Shai-Hulud," a worm spreading through compromised npm packages that harvests developer credentials from infected machines.
- November 2025 — Suno says it detected a "limited security incident" — a single employee compromised via Shai-Hulud — and states it was "quickly contained."
- July 15, 2026 — 404 Media publishes a report based on material shared by a hacker using the handle ellie.191, who says they used credentials harvested via the Shai-Hulud campaign to access Suno's source code, customer list, and Stripe payment data.
- July 20, 2026 — HaveIBeenPwned adds the breach to its database, confirming 55.3 million unique accounts.
- July 22, 2026 — SecurityWeek reports both the Suno and Paidwork breaches in the same roundup, noting HIBP flagged both on consecutive days.
Part 2: What each company actually said — and what that means
When people talk about a company "confirming" a data breach, they usually picture something like a press release, a notification email, or a banner on the login page. In practice, that's not what confirmation looks like — and comparing what Paidwork and Suno actually did shows why that gap matters.
Paidwork: total silence
As of this writing, there is no statement from Paidwork anywhere — not on its website, not in a press release, not in response to press inquiries. This is the simpler case: whatever legal or PR reasoning is behind it, users have no company-provided information to go on. Only the independent analysis from HaveIBeenPwned and the security outlets who reviewed the leaked dataset fills that gap.
Suno: on the record, twice, and still not enough
Suno's case is more instructive, because on the surface it looks like the opposite of Paidwork's: the company did respond — twice, six days apart.
First, to 404 Media and Engadget, in a statement attributed only to "a Suno spokesperson":
"In November of 2025, we determined that Suno had been the subject of a limited security incident that was quickly contained. At the time, we immediately conducted an investigation and verified that the incident primarily involved outdated source code that is no longer in use at Suno and that no sensitive personal information was compromised. Importantly, Suno does not have access to customers' full credit card numbers in Stripe."
Read closely, this statement does several things at once:
- It confirms an incident happened — that part is not in dispute.
- It narrows the scope to "outdated source code... no longer in use," which is true of the AI-training files but doesn't address the customer and payment data HIBP separately confirmed was in the same leak.
- It says "no sensitive personal information was compromised" — a claim HaveIBeenPwned's own listing appears to contradict, since it includes phone numbers, physical addresses, and partial payment card details.
- It clarifies, accurately, that Suno never held full card numbers — true, but not really the point in dispute, since Stripe (the payment processor) is the one that holds those, not any merchant using it.
That same statement directly addressed why no one got a notification email: Suno said it had concluded individual breach notifications "were not warranted under applicable privacy laws" — a specific legal justification, not just silence. It separately noted it had filed a California-mandated disclosure about its AI training data, a different legal requirement, unrelated to the breach itself.
Six days later, once HaveIBeenPwned's confirmed numbers made the story bigger, TechCrunch pressed further and got Suno spokesperson Rachel Racusen on the record by name — she did not dispute the 55.3 million figure and confirmed the November 2025 incident.
The nuance worth sitting with
Paidwork's silence is unexplained. Suno's silence toward users specifically was a deliberate legal judgment call, stated on the record. That's a meaningful difference in intent — but not in outcome. Neither the "say nothing" approach nor the "explain to reporters why individual notice wasn't required" approach results in the person whose bank details, address, or phone number was exposed getting a direct heads-up. In both cases, that person's best source of truth is a third party — HaveIBeenPwned — not the company that held their data.
That's the actual reason breach-checking tools exist, worth stating plainly: company statements, when they exist at all, are written for reporters and, eventually, regulators and plaintiffs' attorneys — not as a substitute for checking your own exposure directly.
What the two breaches have in common
- Neither company told its users directly. Both breaches came to light through HaveIBeenPwned and independent reporting, not company disclosure.
- Both involve financial data, not just credentials — bank account numbers and transaction history for Paidwork, partial card data and purchase history for Suno.
- Both breaches sat undetected or undisclosed for months before becoming public — Paidwork's intrusion reportedly dates to March 2026 and only surfaced in July; Suno says it knew about its incident since November 2025 and still didn't notify users directly, on its own legal reasoning.
What to do, either way
Sources:
- Have I Been Pwned — Paidwork
- Have I Been Pwned — Suno
- Help Net Security — confirms Paidwork "has remained silent... with no public acknowledgment issued," citing The Register's original reporting
- Hall Attorneys — investigations page — also reports on Paidwork's non-acknowledgment. Note: plaintiff-side law firm soliciting litigation clients, not an independent news outlet — cited only as secondary confirmation of a fact already reported by The Register/Help Net Security.
- SecurityWeek — joint roundup, confirms no response received from either company as of July 22
- 404 Media — original Suno report, containing the first, unnamed spokesperson statement
- Engadget — independently obtained the same statement
- Music Business Worldwide — confirms the "not warranted under applicable privacy laws" quote and the California disclosure detail
- TechCrunch, via Music Business Worldwide — source for the Rachel Racusen on-the-record confirmation
- Socket.dev — technical breakdown of the Shai-Hulud attack vector
- CyberInsider — HIBP data-category breakdown used for the contradiction analysis
- Cyber Daily — attacker handle and technical detail