Substack confirmed an incident in which an unauthorized third party accessed limited user data, including email addresses, phone numbers, and other unspecified internal metadata. The company said the access occurred in October 2025 and that passwords, credit card numbers, and other financial information were not accessed; CEO Chris Best stated Substack identified evidence of the issue in early February and has since fixed the underlying problem and opened an investigation.
Public reporting indicates the breach may be connected to data posted on criminal forums: a threat actor allegedly leaked a database on BreachForums containing 697,313 records and claimed the data was obtained via a “noisy” scraping method that was quickly patched. Substack has not disclosed the number of affected users or the precise technical root cause, and both reports note the company advised users to be cautious about phishing attempts leveraging the exposed contact details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned published an entry for the Substack breach, describing about 663,000 affected account records from the October 2025 incident and noting the data was more broadly circulated in February 2026. The listing said the exposed data included email addresses, public profile information, and phone numbers for a subset of users.
On February 5, 2026, Substack confirmed the breach in notifications to users and public statements from CEO Chris Best. The company warned affected users to watch for phishing and suspicious emails or texts, and said it was taking steps to improve security controls and processes.
Substack said it discovered evidence of the incident on February 3, 2026, identified the underlying system issue, fixed or patched it, and began an internal investigation. The company later said it had no evidence of active misuse at that time.
On February 2, 2026, a threat actor posted or advertised an alleged Substack dataset on BreachForums, claiming to have obtained roughly 663,000 to nearly 700,000 user records. Reports said the data included contact details and other account-related fields.
Substack said an unauthorized third party accessed limited user data in October 2025. The exposed information included email addresses, phone numbers, and internal account metadata, while passwords and financial or payment data were reportedly not accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.