In early February 2026, Substack, the popular newsletter and publishing platform, confirmed a data breach that exposed user data. The company revealed that an unauthorized third party accessed parts of its systems in October 2025. Substack discovered the breach on February 3, 2026, and subsequently notified its users.
According to Substack's official communication, the compromised data includes user email addresses and phone numbers. Some internal metadata associated with accounts may also have been exposed. However, Substack assured users that passwords, credit card numbers, and other financial details were not accessed. Security researchers have reported that a database of approximately 700,000 user records has appeared on a hacking forum, although Substack has not confirmed the exact number of affected accounts. Have I Been Pwned reports 663k account holder records were exposed.
Substack CEO Chris Best emailed users to apologize for the incident. In the email, Best stated that the company is conducting a full investigation and has patched the vulnerability that allowed the access. He also mentioned that Substack is taking steps to improve its systems and processes to prevent similar incidents in the future.
The timeline of the breach raises concerns, as the initial access occurred in October 2025, but the breach was not detected until early February 2026. This delay gave the attackers a significant window to potentially exploit the stolen data.
Security experts advise users to be cautious of potential phishing attempts and scams. With access to email addresses and phone numbers, attackers could send targeted phishing emails or SMS messages. Users should be wary of suspicious communications and avoid clicking on links or providing personal information.
The Substack data breach serves as a reminder of the importance of data security and the potential risks associated with online platforms. While Substack has taken steps to address the issue, users should remain vigilant and take precautions to protect their personal information.



















