Substack user contact-data incident

Unauthorized access to limited Substack user data, identified and disclosed in February 2026. Company-confirmed email, phone, and internal-metadata exposure with a separately measured HIBP corpus.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to limited Substack user data, identified and disclosed in February 2026. [2]

Impact

Company-confirmed email, phone, and internal-metadata exposure with a separately measured HIBP corpus. [1][2]

Documented data types include:

  • Contact information — Email addresses and phone numbers confirmed by Substack; only a subset of HIBP corpus records contained phone numbers. [1][2]

A cited record reports 663,121 records (Unique email addresses represented in HIBP’s verified corpus; not a Substack-confirmed count of people, account holders, subscriptions, accounts, or total rows; as of 2026-02-06). [1][2]

Substack said it had no evidence that user data was being misused and advised users to be cautious with emails and texts. [2]

Substack said other unspecified internal metadata was accessed; HIBP described public profile information such as publication names and bios in its corpus. [1][2]

Substack said an unauthorized third party accessed limited user data without permission after an issue allowed access to parts of its systems. [2]

Substack said credit-card numbers, passwords, and other financial information were unaffected. [2]

Timeline

  1. Documented event

    HIBP BreachDate; Substack said the unauthorized access occurred in October 2025 but did not publicly confirm the exact day in the preserved company email.

    [1][2]
  2. Public disclosure

    Date TechCrunch published Substack’s confirmation and quoted the user notification.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Substack said it identified the issue in February 2026, fixed the problem, and began an investigation. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]