If the lawyers at Suno are getting bored of all the copyright infringement lawsuits they are having to respond to, now they can distract themselves by swotting up on a whole different strand of law. Because the music AI company is being sued not once but twice over last year’s big data breach.
That data breach happened last November but only recently came to light thanks to reporting by 404 Media. Data breach monitor Have I Been Pwned subsequently revealed that personal data connected to 55.3 million Suno users was grabbed by hackers who gained access to the AI company’s servers.
That was only possible, says one of the class action lawsuits filed in recent days, because Suno stored its user data in a “negligent and/or reckless manner”. In fact, the lawsuit alleges, the “mechanism of the cyberattack and potential for improper disclosure” of the user data “was a known risk” to Suno, which means the company “was on notice” that a failure to address the issues could result in data leaking.
According to Have I Been Pwned, the stolen Suno data included names, addresses, email addresses, phone numbers, purchase histories and partial payment card details.
Which means, the lawsuit continues, Suno’s data security failure means its users “are now at a significantly increased and certainly impending risk of fraud, identity theft, intrusion of their privacy, and similar forms of criminal mischief, risk which may last for the rest of their lives”.
And as a result, those users will have to “devote substantially more time, money and energy to protect themselves, to the extent possible, from these crimes”.
Suno has never formally alerted its users to the data breach, but in response to the recent media coverage a spokesperson confirmed a cybersecurity incident did occur last November.
The lawsuits also reference this lack of communication. One of them says that users “were wholly unaware of the data breach for nine months until public news sources disclosed the breach”, adding that, at the time of filing the lawsuit, “defendant has not provided any notice regarding the data breach”.
For privately owned companies in the US, rules regarding how companies communicate data breaches are found in state-level laws and therefore differ around the country in terms of when breaches need to be declared and communicated, and what that process involves.
But guidance published by Boston-based law firm Ropes & Gray explains that, “all 50 states have data breach notification laws with varying requirements, but generally the entity that owns the data must notify natural persons if there is unauthorised access to certain categories of their ‘personal information’”.
The same guidance also notes that ‘companies with customers outside the US also need to consider notifications to foreign data protection authorities, including the EU/UK requirements under the GDPR for notice to the supervisory data protection authority within 72 hours of becoming aware of a breach”.
The two lawsuits are respectively fronted by Suno users Frank Rugnetta and Alec Pilavian. They have both been filed in Massachusetts where Suno is based and both seek class action status, so they could represent all US Suno users affected by the data breach.
The litigation specifically accuses Suno of negligence; breach of implied contract; breach of the implied covenant of good faith and fair dealing; and unjust enrichment.
404’s original article on the big Suno hack also reported that the hacked data included the AI platform’s source code which revealed that the music AI company had scraped songs and lyrics from Deezer, Genius and YouTube to train its AI models.
Though that revelation is more relevant to the various copyright infringement lawsuits against Suno, and for today we’re allowing Suno’s lawyers to only think about data protection law.