AI Security AI安全 4h ago Updated 1h ago 更新于 1小时前 49

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts Suno、Paidwork数据泄露影响数千万账户

Tens of millions of user records were compromised in breaches affecting AI music generator Suno and gig-work platform Paidwork. Suno's leaked source code reveals extensive scraping of copyrighted material from platforms like Deezer, YouTube, and Genius. The Suno breach exposed 55.3 million email addresses, phone numbers, and partial Stripe payment data, including card types and expiration dates. Paidwork claims no confirmed evidence of compromise despite a leaked 11 GB database containing data f AI音乐生成平台Suno遭黑客攻击,泄露源代码及5530万用户邮箱等敏感数据。 泄露的Suno源代码证实平台曾从Deezer、YouTube等平台抓取音乐和播客内容。 零工平台Paidwork被指泄露约2330万用户数据,包含密码哈希、银行账号及财务交易记录。 尽管有第三方报告,Paidwork官方目前尚未确认系统遭到入侵,正由安全团队调查。

75
Hot 热度
65
Quality 质量
70
Impact 影响力

Analysis 深度分析

TL;DR

  • Tens of millions of user records were compromised in breaches affecting AI music generator Suno and gig-work platform Paidwork.
  • Suno's leaked source code reveals extensive scraping of copyrighted material from platforms like Deezer, YouTube, and Genius.
  • The Suno breach exposed 55.3 million email addresses, phone numbers, and partial Stripe payment data, including card types and expiration dates.
  • Paidwork claims no confirmed evidence of compromise despite a leaked 11 GB database containing data for approximately 23.3 million users.

Why It Matters

This incident highlights critical vulnerabilities in AI companies' data security practices and raises significant legal and ethical concerns regarding copyright infringement through automated scraping. For practitioners, it underscores the necessity of robust data governance and transparent sourcing mechanisms in generative AI models to mitigate liability and maintain user trust.

Technical Details

  • Suno Breach Scope: The intrusion involved the theft of proprietary source code and user data, specifically exposing 55.3 million unique email addresses and sensitive financial information via Stripe payment records.
  • Data Scraping Evidence: Leaked code demonstrated that Suno aggregated audio and textual data from major third-party services, including Deezer, YouTube, and Genius, without apparent authorization.
  • Paidwork Data Exposure: An 11 GB database leak allegedly contained 23.3 million unique emails, alongside names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, and transaction histories.
  • Verification Status: While Have I Been Pwned (HIBP) analyzed and confirmed the volume of exposed data, Paidwork has publicly stated there is no confirmed evidence of a system compromise and has initiated an internal security investigation.

Industry Insight

  • Copyright Liability Risks: The exposure of scraping methodologies in Suno's code may lead to increased litigation from media and content platforms, forcing AI developers to adopt stricter data licensing agreements.
  • Security Audits Necessity: Companies handling large-scale user data must prioritize regular security audits and penetration testing, particularly when integrating third-party payment processors and external data sources.
  • Transparency Expectations: Users and regulators are increasingly demanding transparency regarding data usage and security incidents; proactive disclosure and clear communication strategies are essential for maintaining brand integrity during crises.

TL;DR

  • AI音乐生成平台Suno遭黑客攻击,泄露源代码及5530万用户邮箱等敏感数据。
  • 泄露的Suno源代码证实平台曾从Deezer、YouTube等平台抓取音乐和播客内容。
  • 零工平台Paidwork被指泄露约2330万用户数据,包含密码哈希、银行账号及财务交易记录。
  • 尽管有第三方报告,Paidwork官方目前尚未确认系统遭到入侵,正由安全团队调查。

为什么值得看

本文揭示了AI生成内容(AIGC)公司在数据合规与版权获取方面的潜在风险,特别是通过源代码泄露暴露出的非授权数据抓取行为。同时,大规模用户数据泄露事件凸显了AI初创企业及数字服务平台在网络安全防护上的脆弱性,对从业者的数据治理和隐私保护策略具有重要警示意义。

技术解析

  • Suno数据泄露详情:黑客于2025年11月入侵Suno,泄露内容包括源代码和用户数据。HIBP分析确认涉及5530万个唯一邮箱地址,以及电话、姓名、物理地址、Stripe支付记录(含卡类型、有效期及后四位)等。
  • 版权争议证据:泄露的Suno源代码显示,该平台曾从Deezer、YouTube和Genius等主要音乐和播客平台进行数据抓取(scraping),这为AI训练数据的来源合法性提供了直接的技术证据。
  • Paidwork数据泄露规模:威胁行为者泄露了一个11GB的数据库,声称包含约2200万用户信息。HIBP分析识别出2330万个唯一邮箱,数据字段包括姓名、密码哈希、出生日期、电话号码、银行账号、财务交易及用户画像信息。
  • 响应状态:SecurityWeek联系双方寻求评论,Paidwork回应称目前尚无确凿证据证明其系统或账户受到侵害,已将此事升级给安全团队进行调查。

行业启示

  • AI数据源透明度与合规性:AI公司应审视其训练数据的获取方式,避免依赖未授权的网页抓取,以规避潜在的版权诉讼和品牌声誉风险。
  • 强化用户数据安全治理:面对日益频繁的大规模数据泄露,企业需加强密码存储安全(如使用更先进的哈希算法)、支付信息隔离及定期安全审计,降低敏感数据泄露后的危害。
  • 危机公关与验证机制:在收到第三方安全报告时,企业应建立快速、透明的内部验证流程,并及时向用户通报真实情况,避免因信息不透明引发更大的信任危机。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Creative AI 创意AI