The Hacker Found the Manifest. Your AI Vendor Keeps One Too.

The Hacker Found the Manifest. Your AI Vendor Keeps One Too.

THE TECHNOLOGY BLIND SPOT

The file was named youtube_music. When last updated, it recorded 2,013,545 ingested music clips. A companion file kept the ledger in hours: 113,879 hours of YouTube Music, 62,117 hours of Pond5 stock tracks, 19,514 hours from a classical sheet music archive, 12,287 hours of Deezer, 17,615 hours of lyrics scraped from Genius. Sum the categories and the total runs to decades of continuous audio, inventoried with the indifference of a freight schedule.

Nobody at Suno published that ledger. A hacker pulled it from the company's source code and handed it to the journalists at 404 Media, who published the details on July 15, 2026. The code, which appears to date from 2023 and 2024, contains the scraping instructions themselves. One comment lists the targets: genius_hq, youtube_music, freesound, jamendo, deezer. Another adds a line of housekeeping: “non-music will be filtered out.”

Readers of this series know the method. The Technology Blind Spot takes a specific, documented event in one market and runs it against legal practice, because attackers rarely retire a working technique. They prove it in one industry, then carry it into adjacent markets the moment the economics favor the move. I watched the cycle from inside enterprise technology: in 2011, intruders breached RSA, a security vendor, and months later Lockheed Martin, Northrop Grumman, and L-3 Communications reported intrusions built on the stolen data. [See I Was Inside EMC When Hackers Stole the Keys to 40 Million Doors, The Technology Blind Spot (2025).] The attackers did not start with the defense contractors. They started with the vendor the defense contractors trusted. The worm that opened Suno's door spreads through the same npm software registry that nearly every AI vendor, legal ones included, builds on. The cycle is already in motion. This piece maps where it lands next.

Here is what makes the breach interesting to a lawyer rather than a musician. Suno had already told a federal court most of this. In its August 2024 answer to the record labels' copyright suit, the company stated that its “training data includes essentially all music files of reasonable quality that are accessible on the open Internet.” The hack did not contradict that representation. It itemized it. An admission is a sentence a lawyer drafted. An inventory is a document an engineer maintained. Courts treat those two artifacts very differently, and so should you.

The Suno breach demonstrates a risk no legal AI due diligence checklist currently prices: when an AI vendor is breached, its training and data-handling representations stop being marketing and become checkable evidence. Your firm's uploads sit in the same kind of ledger.

What the Hacker Actually Took

According to 404 Media's reporting, the intrusion reached well past the training pipeline. The hacker, who uses the name ellie.191, told the outlet they got in by hitting a Suno employee with a supply-chain worm that spreads through compromised npm packages and harvests credentials. From there they viewed account information for hundreds of thousands of Suno customers along with Stripe payment records. The Recording Industry Association of America had accused Suno of ripping songs directly from YouTube and circumventing the platform's copy protection; 404 Media reported that the hacked data confirms the accusation.

The timeline deserves more attention than the scraping. Suno determined in November 2025 that it had suffered what its spokesperson later called a limited security incident, quickly contained. The company concluded that individual breach notifications “were not warranted under applicable privacy laws.” Its customers learned about the intrusion in July 2026, from journalists, and some of the exposed customers confirmed to 404 Media that no notice had ever reached them. Eight months separated the vendor's discovery from its customers' first knowledge, and the disclosure, when it came, arrived by a hacker's choice rather than the vendor's.

Notice the structure of the exposure. Three separate things leaked, and one clock ran silently behind them. The customer data. The provenance ledger. The gap, if any, between the ledger and the representation. Behind all three, a vendor that decided for eight months that none of it required a notice. Each element lands differently in litigation, and each has a direct analog in legal technology.

Your Vendor Keeps the Same Ledger

Every trained model has manifests. Dataset inventories, ingestion pipelines, deduplication logs, provenance records: these exist because engineers cannot build or debug a model without them. Their existence is an engineering necessity, not a scandal. The scandal potential lives entirely in the delta between what the manifest records and what the vendor represents.

Legal AI vendors make representations constantly. We never train on customer data. Our models learn only from public legal sources. Firm inputs are deleted after thirty days. Each sentence appears in a contract, a trust center page, or a sales deck. None of it is verifiable from outside the vendor. A SOC 2 report does not test it; the audit boundary stops at controls, not corpora. [See Your SOC 2 Audit Stops Where Your AI Privilege Risk Begins, The Technology Blind Spot (2026).] Due diligence, as most firms practice it, audits the vendor's promises. A breach audits the vendor's behavior. The asymmetry matters because the manifest is the one document a vendor never volunteers. It sits outside every SOC 2 scope, every trust center page, every security questionnaire your firm has ever sent. Training manifests surface exactly two ways: compelled in discovery, or taken in a breach. Suno's surfaced the second way.

Run the Suno fact pattern against a legal AI vendor and three exposures fire at once.

First, the uploads themselves. The Stripe records in the Suno hack correspond, in a legal vendor's systems, to the documents your associates uploaded: the draft complaint, the deposition excerpt, the settlement memo. Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information. ABA Formal Opinion 483 requires firms to notify clients when a breach compromises their material confidential information, and it contains no carve-out for breaches that happen at a vendor. Suno concluded its own customers required no notice at all. A vendor that reasons the same way starts your ethical clock on a breach you have not been told about.

Second, the manifest. If a vendor's ingestion logs show firm inputs in a training corpus after the contract promised otherwise, every no-training clause the vendor ever signed converts into a breach-of-contract exhibit. If the logs show the opposite, they become the vendor's best defense. Either way, the representation stops being a matter of trust and becomes a matter of record, held by whoever holds the stolen files. In March 2026, a federal magistrate judge in Denver ordered a contractual safeguard inquiry for any AI vendor receiving confidential information in Morgan v. V2X. A leaked manifest is exactly the document that inquiry would test those safeguards against. The record labels have already shown what provenance evidence does to damages exposure: in May 2026, UMG and Sony moved to expand their case from 560 works to 61,026 identified in Suno's training data through audio fingerprinting, lifting the theoretical statutory ceiling from roughly $84 million to more than $9 billion. The judge has not ruled. The number moved because the evidence did.

Third, the gravity well. Hacked material does not stay in one dispute. Once provenance data leaks, everyone with a motive cites it: opposing counsel arguing waiver under the reasoning of United States v. Heppner, malpractice plaintiffs arguing the firm should have known, insurers reading the firm's application answers against the new record. [See 17 Subprocessors Deep, The Technology Blind Spot (2026).]

The Attorney Who Tested This in 2012

Edward White ran an intellectual property practice in Oklahoma City. In February 2012 he sued West Publishing and Reed Elsevier, because both companies had downloaded his briefs from PACER, converted them into searchable records, and sold access through Westlaw and Lexis. White wrote those briefs. He held registered copyrights. He lost. In July 2014, Judge Jed Rakoff of the Southern District of New York held the copying was transformative fair use, in part because no licensing market for attorney briefs exists; the transaction costs would be prohibitive.

The profession barely noticed. White's loss meant every brief a firm files becomes lawful raw material for any company building a research product on top of it, and the model training pipelines assembled a decade later inherited that permission structure without asking twice.

Twelve years after White filed, the same judge decided the other end of the pipeline. In United States v. Heppner, Judge Rakoff held on February 17, 2026 that a criminal defendant's exchanges with a consumer AI platform carried neither privilege nor work product protection, resting in part on the vendor's own privacy policy, which disclosed that user inputs train the model and may reach third parties. [See Your AI Tool Doesn't Keep Secrets, The Technology Blind Spot (2026).] One judge, two rulings, one lesson: what leaves your firm through the courthouse door is fair game for the corpus, and what leaves through the prompt box may carry no protection at all. The manifest is where both flows come to rest.

“Publicly Available” Is Doing No Legal Work

After the hack, Suno reached for the same two words it has used since the record labels sued: publicly available. Legal AI vendors lean on the identical phrase, and it deserves a closer look than it usually gets, because it sounds like a defense while functioning as a description.

Copyright law contains no publicly available exception. The fair use factors in 17 U.S.C. § 107 never ask whether the work was easy to reach. When two federal judges blessed AI training as fair use in mid-2025, in Bartz v. Anthropic and Kadrey v. Meta, the variable that mattered was acquisition: Judge Alsup called training on lawfully acquired books exceedingly transformative while condemning the pirated copies in the same opinion. [See The Better Your AI Gets, the Less You Can Own It, The Technology Blind Spot (2026).] Availability decided nothing. Acquisition decided everything, and the Suno manifests are a record of acquisition.

The Suno filings now show how a manifest tests a representation clause by clause. The company's answer told the court its training data was gathered “abiding by paywalls, password protections, and the like.” The leaked code names Deezer and Pond5 among the sources, and both require payment for access. Whether that tension survives scrutiny is a question for the Massachusetts court; that the question can be asked at all is the manifest's doing. A representation drafted at the level of principle just met a log file kept at the level of fact.

For a law firm the phrase cuts harder in the other direction. Everything your firm uploads to a vendor is, by definition, not publicly available. A vendor whose entire data ethic rests on the words publicly available has told you precisely nothing about the one category of data you care about, and the manifest is the only document that ever will.

The Strongest Objection

The serious counterargument runs like this. Suno is a consumer music app fighting an existential copyright war. Legal AI vendors operate under enterprise contracts with no-training clauses, data processing agreements, zero-retention options, and named subprocessors. The manifest details come from a pseudonymous hacker whose files no court has authenticated. And the underlying scraping of public court filings is not even wrongful; White settled that in the database vendors' favor a decade ago. On this view, the Suno hack is a music industry story wearing a technology headline.

Every clause of that objection is accurate, and the conclusion still fails, for one structural reason: the contract layer protects you only while the infrastructure layer holds. The past year supplied counterexamples from the top of the market. Anthropic shipped an npm package that exposed roughly half a million lines of its own source code. BeyondTrust researchers found a command injection flaw in OpenAI's Codex cloud environment that exposed GitHub credential data. The Suno intrusion itself reportedly began on the same surface: a worm riding compromised npm packages, the software pipeline every vendor shares. [See Your AI Agent Was Built by an AI. SOC 2 Audited Neither., The Technology Blind Spot (2026).] Enterprise paper describes what the vendor may do. A breach reveals what the vendor did. The no-training clause was never the control; it was the promise the control was supposed to enforce. When the infrastructure fails, the promise and the evidence of its performance leak together.

Where the Analogy Breaks

Two limits deserve plain statement. No legal AI vendor has yet suffered a breach that exposed training manifests. This piece projects a demonstrated failure mode from an adjacent industry onto legal technology, and projection is not precedent. Hacked evidence also faces authentication problems in court: a party can challenge provenance, chain of custody, and the possibility of edits, and sometimes wins. The Suno files carry weight for two reasons: they align with what Suno had already conceded in a signed federal filing, and Suno's own statement acknowledged the incident and described the stolen material as its outdated source code, a characterization that disputes the code's currency, not its authenticity. A leaked manifest that a vendor flatly disowned would face a harder road.

Neither limit rescues the diligence gap. The uploads exposure requires no manifest at all, only a breach, and breaches at AI vendors require no projection. They are last quarter's news.

Thursday Morning

Send your legal AI vendor's account manager one email with two requests.

Request one: a written representation, signed by someone with authority to bind the company, identifying every category of data used to train or fine-tune any model that processes firm inputs, and stating whether any firm-uploaded content appears in any training or evaluation corpus, past or present. The vendor's engineers can answer this from their own manifests in an afternoon. A vendor that cannot answer is telling you the manifest says something the sales deck does not.

The second request: the specific section of your master agreement that obligates the vendor to notify the firm when the vendor itself is breached, with the deadline stated in hours, and confirm in writing that the duty covers training infrastructure, not just production systems. While you wait for the reply, pull the agreement and read the clause yourself. If the notification duty is missing, silent on training systems, or keyed to discovery language the vendor controls, you found the gap before an incident finds it for you.

Formal Opinion 483 sets your duty to your clients. This email establishes whether the vendor's duty to you can arrive in time for you to meet it.

The file was called youtube_music. Somewhere in your vendor's repository sits a file with a different name and the same job: a running count of everything the model has consumed, kept accurately because the engineers need it, and read by exactly no one on your side of the contract. The Suno hack settled only one question about ledgers like that. They do not stay private. The open question is who reads yours first: the vendor's engineers, a federal judge, or someone who was never meant to see it at all.

About the Author

JD Morris is Co-Founder and COO of LexAxiom, an Agentic AI platform for the business of law. Over a 25-year career, he has built and scaled enterprise technology products across Dell, EMC, VMware, and Cisco, including the first exabyte eDiscovery platform. He holds dual MBAs from Columbia Business School (Finance) and UC Berkeley Haas (Marketing), a Master of Legal Studies in Cybersecurity Law from Texas A&M, and a Master of Engineering from George Washington University. He writes The Technology Blind Spot on the intersection of emerging technology and law. Connect with him on LinkedIn at www.linkedin.com/in/jdavidmorris, on X at @JDMorris_LTech, or on Bluesky at @JDMorris-ltech.bsky.social.

References

1. Jason Koebler, Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius, 404 Media (July 15, 2026), https://www.404media.co/hack-reveals-suno-ai-music-generator-scraped-youtube-deezer-and-genius/.

2. Maggie Harrison Dupré, Hackers Expose How AI Music App Suno Stole Decades Worth of Copyrighted Music, Futurism (July 17, 2026), https://futurism.com/artificial-intelligence/hacker-ai-music-suno-copyright.

3. Suno Scraped YouTube, Deezer and Genius to Train Its AI, Hacked Code Reveals, Music Bus. Worldwide (July 16, 2026), https://www.musicbusinessworldwide.com/suno-scraped-youtube-deezer-and-genius-to-train-its-ai-hacked-code-reveals/.

4. Answer of Defendant Suno, Inc., UMG Recordings, Inc. v. Suno, Inc., No. 1:24-cv-11611-FDS, ECF No. 28 (D. Mass. Aug. 1, 2024).

5. White v. West Publ'g Corp., 29 F. Supp. 3d 396 (S.D.N.Y. 2014).

6. United States v. Heppner, No. 1:25-cr-00503-JSR, ECF No. 27 (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.).

7. Morgan v. V2X, Inc., No. 25-cv-01991-SKC-MDB (D. Colo. Mar. 30, 2026).

8. Bartz v. Anthropic PBC, No. 3:24-cv-05417-WHA (N.D. Cal. June 23, 2025).

9. Kadrey v. Meta Platforms, Inc., No. 23-cv-03417-VC, 2025 WL 1752484 (N.D. Cal. June 25, 2025).

10. Model Rules of Pro. Conduct r. 1.6(c) (Am. Bar Ass'n 2024).

11. ABA Comm. on Ethics & Pro. Resp., Formal Op. 483 (2018).

12. 17 U.S.C. § 107 (2018).

To view or add a comment, sign in

More articles by JD Morris

Others also viewed

Explore content categories