Recommended Free Tools
Substack says an unauthorized party accessed some users’ email addresses, phone numbers and unspecified internal metadata in October 2025. The company says passwords, credit card numbers and other financial information were not accessed. Substack has not disclosed how many users were affected or the technical cause; a hacker’s reported claim of about 700,000 records is unconfirmed.
What happened in the Substack data breach?
Substack told users that an unauthorized third party accessed limited account data in October 2025. The company says it identified the issue on February 3, 2026, fixed the systems problem and began an investigation. It has not disclosed the technical weakness that enabled the access. TechCrunch and The Record reported the company’s notification and response on February 5, 2026.
Substack CEO Chris Best apologized in the email to users, as quoted by TechCrunch: “I’m reaching out to let you know about a security incident that resulted in the email address and phone number from your Substack account being shared without your permission.” Best also said, “I’m incredibly sorry this happened. We take our responsibility to protect your data and your privacy seriously, and we came up short here.”
What information did the Substack breach expose?
Substack identified email addresses, phone numbers and “other internal metadata” as accessed. The company has not specified what that metadata includes, so it should not be treated as a confirmed list of additional exposed fields.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
Substack said passwords, credit card numbers and other financial information were not accessed. That is the company’s assurance as reported by news outlets, rather than an independently established account of every aspect of the incident.
Was my Substack account affected?
Substack has not disclosed a confirmed number of affected users, and its notification does not establish from the reviewed coverage whether any particular reader’s account was involved. CSO interpreted the notification as applying to people with Substack accounts, rather than people who only subscribe to a creator’s newsletter by providing an email address. That distinction is CSO’s interpretation, not a separate explicit confirmation from Substack. CSO’s report describes that reading.
An unidentified hacker claimed that about 700,000 records were involved. The Record said the size and scope of the claim were unclear, and CSO reported the figure as unconfirmed. It is not an official breach count.
Should you worry about phishing texts or emails?
Substack said it had no evidence that the accessed information had been misused and advised users to be cautious with suspicious emails and texts. That statement does not prove misuse is impossible. Because email addresses and phone numbers were among the data categories the company said were accessed, treat unexpected messages claiming to be from Substack with care.
- Do not click links or open attachments in unexpected messages; go to Substack through its app or by entering its address yourself.
- Be wary of messages asking for your password, payment details or a verification code.
- If a message creates urgency or asks you to “secure” your account through a link, verify it through an official channel before acting.
What remains unknown?
- The confirmed number of affected users.
- The full meaning and scope of “other internal metadata.”
- The technical cause of the unauthorized access.
- Whether the investigation has established additional facts beyond the company’s reported notification and assurances.
The reported timeline is limited: Substack says the access occurred in October 2025 and that it identified the issue on February 3, 2026. TechCrunch, The Record and CSO published their reports on February 5, 2026. The company said it fixed the systems problem and was taking steps to improve its systems and processes.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

