If you’re a Substack user, your data might’ve been leaked
Substack has informed some of its users of a data breach in which email addresses and phone numbers were stolen. The attack occurred in October 2025, but the breach was first discovered on February 3rd, 2026, reports BleepingComputer.
According to Substack CEO Chris Best, an unauthorized party gained access to limited user data. No passwords, payment details, or other financial data were affected. Some internal metadata was leaked.
Substack states that the security flaw has now been fixed and that a full investigation is underway. There are currently no signs that the stolen data has been misused, but users are urged to be cautious and watch out for suspicious emails or text messages.
The company has not confirmed how many accounts have been affected. A data set was published on the hacker forum Breachforums that allegedly contains approximately 697,000 records from Substack.