Substack Discovers Breach Exposing 697,000 User Records

Publishing platform vulnerabilities affect creators and subscribers who depend on email as their primary distribution channel.

Illustration: Substack Discovers Breach Exposing 697,000 User Records
AI-generated illustration · Sylvaris

Four-month dwell time

<cite index="61-1,61-6">Substack discovered evidence of unauthorized system access on February 3, 2026, determining that the breach had occurred in October 2025</cite>. <cite index="57-5,57-6">The incident was not a traditional server penetration but a scraping attack targeting the platform's API, with threat actors exploiting a vulnerability before security systems triggered and patched the flaw</cite>.

<cite index="61-5">The company began notifying users about compromised email addresses, phone numbers, and internal metadata</cite>. <cite index="55-2,55-3">The breach exposed 663,000 account holder records containing email addresses along with publicly visible profile information such as publication names and bios, with a subset also including phone numbers</cite>.

What was not compromised

<cite index="61-7">CEO Chris Best stated in the notification that passwords and payment card information were not accessed</cite>. <cite index="62-8">The breach happened in October 2025, meaning data was exposed for up to four months, though the company confirmed it did not include credit card numbers, passwords, or financial information</cite>.

<cite index="62-3,62-4">Substack's default access method relies on email authentication via magic links rather than passwords, which removes the problem of password compromise and phishing attacks</cite>. The company confirmed it had fixed the system vulnerability and implemented safeguards to prevent recurrence.

Phishing risk ahead

<cite index="54-1,54-2">On February 7, 2026, a threat actor posted the leaked data on darknet forums, with users sharing files containing names, emails, phone numbers, usernames, and account metadata on Telegram channels</cite>. <cite index="56-6">Attackers can mount convincing phishing and impersonation campaigns using email addresses, phone numbers, usernames, profile names, and internal metadata even without password theft</cite>.

<cite index="57-11">Substack CEO Chris Best acknowledged that while financial data remained secure, the exposed information creates a high risk for targeted phishing and doxing</cite>. Security experts drew attention to the four-month gap between the attack and its discovery, a period known as dwell time that allows attackers extended access to systems.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.