Home / Blog / Suno, Paidwork Data Breaches Affect Tens of Millions of…
Tech News

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

By Dillip Chowdary • Jul 22, 2026 • Source: SecurityWeek

Suno and Paidwork suffered data breaches that together affect tens of millions of accounts. Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms, according to SecurityWeek. The scale is not a handful of compromised users: tens of millions of accounts are in scope, and the leak includes both identity fields and secrets that can be reused elsewhere.

The leaked set mixes authentication material with contact and payment-related data. Passwords in a dump enable credential stuffing against any service where users reused the same password. Names, email addresses, and phone numbers support phishing, SIM-swap attempts, and account-recovery abuse. Financial information raises the cost of exposure beyond password reset: it can feed fraud workflows that do not need the original app to still be compromised.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders, this is a reminder that breach impact tracks what you store, not only whether an app feels low-risk. AI music tools and gig/paid-task platforms both end up holding large account graphs. If passwords are stored or recovered in a form that can be leaked usefully, and if financial fields sit next to PII, a single exfiltration event becomes multi-vector. Auth design, encryption at rest, least-privilege data retention, and separation of payment data from general profile tables are the controls that limit how far a dump travels.

SecurityWeek framed the story as two platforms, one pattern: high-volume consumer products with account and money-adjacent data, hit hard enough that tens of millions of accounts matter as a market event, not an isolated incident. Competing products in the same categories will face the same user question after coverage like this: whether their own password hashing, breach-notification process, and payment data boundaries would produce a smaller blast radius under the same conditions.

Practical next steps for anyone with accounts on either service: assume the listed fields may be public, change passwords that were ever reused, treat unsolicited messages that cite name, email, or phone as higher risk, and watch for official notices from each platform on scope and remediation. Builders should audit what they retain in the same buckets that appeared in this leak—passwords, contact identifiers, and financial information—and cut or isolate anything not required for the product to run.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →