Data breach
Substack
- Records
- 664,249
- Breach date
- 9 February 2026Estimated
- Added
- 9 February 2026
What was exposed
5 types of data
- Email addresses664,249
- Phone numbers265,420
- Biographies1
- Names1
- Usernames1
About this breach
Newsletter platform Substack confirmed in early February 2026 that an unauthorized third party accessed limited user data, including email addresses and phone numbers. According to reporting by The Register, the access occurred in October 2025 but went undetected until February 3, 2026, when the company found evidence of a problem with its systems. Substack CEO Chris Best apologized in email notices to users, writing that the email address from their account "was shared without your permission." The company says passwords, credit card numbers, and other financial information were not accessed. The investigation team has indexed 664,249 records in connection with this incident. A post on a cybercrime forum separately advertised roughly 700,000 alleged Substack user records, though Substack has not confirmed that the circulating dataset matches the intrusion it acknowledged.
Breach Timeline
October 2025: An unauthorized third party accessed limited Substack user data, according to the company's notice to users.
February 3, 2026: Substack says it discovered evidence of the systems issue that allowed the access.
February 5, 2026: News of the incident and the company's user notifications became public, reported by outlets including The Register and Security Affairs.
What Information Was Compromised?
Our analysis found the following data types in this breach: Email, Phone Number, Username, Name, and Biography.
The confirmed counts in our indexed data are 664,249 email addresses and 265,420 phone numbers. The amounts of usernames, names, and biographies in the dataset could not be determined precisely. Substack's notice confirmed that email addresses, phone numbers, and internal account metadata were accessed, and stated that passwords and financial data were not. The forum post advertising the alleged dataset claimed it also contained names, user IDs, and profile images, but the company has not confirmed the contents or origin of that dataset.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses and phone numbers are the core building blocks of phishing and smishing attacks. Someone holding this data can send messages that appear to come from Substack, from a newsletter a person subscribes to, or from a payment or verification process, and the messages will look more convincing because they reach the right person.
Exposed phone numbers also raise the risk of SIM-swap attempts, in which an attacker tries to transfer a victim's phone number to a new SIM card to intercept text-based verification codes. Because Substack says passwords were not taken, direct account takeover through leaked credentials is not the primary concern here. The company stated at the time of its notice that it had no evidence the information was being misused, though it urged users to watch for suspicious emails and text messages.
What Is Substack Doing in Response?
According to the company's notice and statements reported by PCWorld and Fox News, Substack has fixed the systems issue that allowed the access, launched a full internal investigation, and begun notifying affected users. CEO Chris Best apologized directly in the notices. The company said it found no evidence that the exposed information was being misused as of the time of notification, and it encouraged users to be cautious with unexpected emails or texts. Substack did not respond to questions from The Register about how many users were affected or whether the forum dataset matches the intrusion.
What Should You Do If You Were Affected?
Be skeptical of unexpected emails or texts claiming to be from Substack, especially messages asking you to verify your account, update payment details, or click a link. Go directly to substack.com instead of following links in messages.
Enable multi-factor authentication on your Substack account and your email account, preferring an authenticator app over SMS codes where possible.
Watch for signs of a SIM-swap attempt on your phone line, such as sudden loss of cellular service.
If you reuse passwords across sites, change them, since contact data can fuel targeted attempts against other accounts.
In the news
- The Register: Substack says intruder lifted emails, phone numbers in months-old breachtheregister.com (opens in a new tab)
- PCWorld: If you're a Substack user, your data might've been leakedpcworld.com (opens in a new tab)
- Fox News: Substack data breach exposes emails and phone numbersfoxnews.com (opens in a new tab)
