Substack Discovers Breach Exposing 697,000 User Records
Publishing platform vulnerabilities affect creators and subscribers who depend on email as their primary distribution channel.
Four-month dwell time
<cite index="61-1,61-6">Substack discovered evidence of unauthorized system access on February 3, 2026, determining that the breach had occurred in October 2025</cite>. <cite index="57-5,57-6">The incident was not a traditional server penetration but a scraping attack targeting the platform's API, with threat actors exploiting a vulnerability before security systems triggered and patched the flaw</cite>.
<cite index="61-5">The company began notifying users about compromised email addresses, phone numbers, and internal metadata</cite>. <cite index="55-2,55-3">The breach exposed 663,000 account holder records containing email addresses along with publicly visible profile information such as publication names and bios, with a subset also including phone numbers</cite>.
What was not compromised
<cite index="61-7">CEO Chris Best stated in the notification that passwords and payment card information were not accessed</cite>. <cite index="62-8">The breach happened in October 2025, meaning data was exposed for up to four months, though the company confirmed it did not include credit card numbers, passwords, or financial information</cite>.
<cite index="62-3,62-4">Substack's default access method relies on email authentication via magic links rather than passwords, which removes the problem of password compromise and phishing attacks</cite>. The company confirmed it had fixed the system vulnerability and implemented safeguards to prevent recurrence.
Phishing risk ahead
<cite index="54-1,54-2">On February 7, 2026, a threat actor posted the leaked data on darknet forums, with users sharing files containing names, emails, phone numbers, usernames, and account metadata on Telegram channels</cite>. <cite index="56-6">Attackers can mount convincing phishing and impersonation campaigns using email addresses, phone numbers, usernames, profile names, and internal metadata even without password theft</cite>.
<cite index="57-11">Substack CEO Chris Best acknowledged that while financial data remained secure, the exposed information creates a high risk for targeted phishing and doxing</cite>. Security experts drew attention to the four-month gap between the attack and its discovery, a period known as dwell time that allows attackers extended access to systems.