Substack, the popular newsletter publishing platform, has confirmed a significant data breach that saw unauthorized access to user email addresses and phone numbers. This incident, which occurred in October 2025, remained undetected until February 3rd of this year, raising concerns about the platform's security monitoring and incident response capabilities.
The breach, described by Substack CEO Chris Best as involving an "unauthorized third party to access limited user data without permission," exposed not only email addresses and phone numbers but also internal metadata. Crucially, Best stated that sensitive financial information, including credit card numbers, and user passwords were not compromised. The company claims the identified security vulnerabilities have since been patched and that a thorough investigation is underway to enhance future defenses.
A Delayed Revelation and a Public Leak
The timeline of this incident is particularly troubling. Data was accessed in October 2025, yet Substack only became aware of the compromise on February 3rd, 2026. This nearly four-month gap between the initial intrusion and discovery is a critical security lapse, suggesting potential deficiencies in their intrusion detection systems or security protocols. Such delays can significantly amplify the impact of a breach, allowing threat actors more time to exfiltrate data or even leverage it for further attacks.
Adding to the concern, reports indicate that a database allegedly containing approximately 697,313 stolen data records from Substack has surfaced on the hacking forum BreachForums. While Substack has not officially confirmed the number of affected accounts, this leak, as reported by Bleeping Computer, suggests a substantial portion of their user base may be impacted. The presence of this data on an illicit marketplace dramatically increases the risk of misuse, despite the company's assertion that there is no current evidence of data being "misused."
Threat Model and User Implications
While Substack has emphasized that financial data and passwords were not accessed, the exposure of email addresses and phone numbers is far from trivial. This information is a cornerstone for many malicious activities, forming the basis of sophisticated phishing campaigns and targeted social engineering attacks. Threat actors can leverage these details to craft highly personalized scams, impersonate legitimate entities, or attempt to gain access to other accounts where users might reuse credentials or security questions based on publicly available information.
For users, this necessitates a heightened state of vigilance. The risk of receiving more convincing phishing emails or smishing (SMS phishing) text messages is now elevated. It would be prudent for all Substack users, especially those whose data may have been compromised, to review their online security practices, enable multi-factor authentication wherever possible, and be exceptionally cautious of any unsolicited communications requesting personal information or urging immediate action.
Substack's response, while acknowledging the breach and promising improvements, must be scrutinized. The company's statement that "security vulnerabilities have now been addressed" is a necessary first step, but the duration of the undetected access is a significant red flag. The promised "full investigation" and "steps to improve our systems and processes" will be crucial indicators of their commitment to robust security going forward. As a platform that facilitates direct communication between creators and their audiences, trust and data integrity are paramount, and this incident erodes that foundation. The platform's attack surface, particularly for user contact information, has been demonstrably exploited, and the long-term implications for user privacy and security will depend heavily on the transparency and effectiveness of Substack's remediation efforts.