Substack Confirms Data Breach Affects Users’ Email Addresses And Phone Numbers

Substack data breach exposed email addresses and phone numbers. Learn what happened, your risk level, and immediate steps to stay safe.
Matilda
Substack Confirms Data Breach Affects Users’ Email Addresses And Phone Numbers
Substack Data Breach Exposes Email Addresses, Phone Numbers Substack has confirmed a data breach exposing users' email addresses and phone numbers to an unauthorized third party. The incident occurred in October 2025 but wasn't detected until February 2026—raising urgent questions about notification delays and platform security. Crucially, payment details, passwords, and financial data remain secure. If you publish or subscribe to newsletters on Substack, here's what you need to know right now to protect your digital footprint. Credit: Rafael Henrique/SOPA Images/LightRocket / Getty Images How the Breach Unfolded: A Five-Month Blind Spot In a direct email to users, Substack CEO Chris Best disclosed that attackers exploited an unknown vulnerability in the company's systems last October. The breach granted access to contact information and internal metadata—but went undetected for nearly five months. Best acknowledged the failure plainly: "We came up short here." Se…