The Suno breach now affects 55.3M accounts

Have I Been Pwned has added the Suno data breach to its database, reporting that the AI music platform’s breach affected 55.3 million accounts.

The newly reported total substantially expands the known scale of the incident. According to Have I Been Pwned, the compromised information included email addresses, phone numbers and, in tens of thousands of Stripe-related records, names, physical addresses, purchase details and partial payment card information.

Have I Been Pwned can be found here: Have I Been Pwned: Check if your email address has been exposed in a data breach

The Suno breach can be found here: Have I Been Pwned: Suno Data Breach

Seemant Sehgal, Founder & CEO, BreachLock had this comment:

“When the disclosed scope of a breach grows this significantly in such a short period, it suggests that either the initial investigation was rushed or the organization lacked adequate visibility into its environment.

“The scale and variety of the exposed data raise serious questions about internal segmentation, security monitoring and incident readiness. Regulators and customers will spend less time focused on the 55.3 million figure than on what Suno knew, when it knew it and how it responded. Organizations that cannot establish what was accessed, when and from where within the first 72 hours will find their disclosure decisions harder to defend than the breach itself.”

Steven Swift, Managing Director, Suzu Labs follows with this::

“Customers have considerable breach fatigue after being notified repeatedly that their names, addresses, email addresses and other personal information have been exposed. At this point, individuals should assume that much of their personal information has already been compromised.

“The AI component is not necessarily the central issue here. There has been no public evidence directly attributing Suno’s security posture to its use of AI-generated code. However, rapidly growing AI companies may rely heavily on AI-assisted development, which can introduce security weaknesses when code is deployed without proper review and testing.

“Most breaches result from organizations failing to follow established security practices. Companies using AI in their applications, automation and infrastructure need a comprehensive security baseline and regular testing to confirm that their controls work. That should include at least annual penetration testing of hosted applications, services, internal networks and devices.

“Testing alone is not enough. Organizations also need to remediate the vulnerabilities that testing identifies. Too many companies conduct annual penetration tests only to receive the same findings year after year.”

Organizations need to consider that being pwned is the worst thing that can happen to them. If they do that, maybe then they will start to take information security seriously.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading