Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Company-confirmed email, phone, and internal-metadata exposure with a separately measured HIBP corpus. [1][2]
Documented data types include:
- Contact information — Email addresses and phone numbers confirmed by Substack; only a subset of HIBP corpus records contained phone numbers. [1][2]
A cited record reports 663,121 records (Unique email addresses represented in HIBP’s verified corpus; not a Substack-confirmed count of people, account holders, subscriptions, accounts, or total rows; as of 2026-02-06). [1][2]
Substack said it had no evidence that user data was being misused and advised users to be cautious with emails and texts. [2]
Substack said other unspecified internal metadata was accessed; HIBP described public profile information such as publication names and bios in its corpus. [1][2]
Substack said an unauthorized third party accessed limited user data without permission after an issue allowed access to parts of its systems. [2]
Substack said credit-card numbers, passwords, and other financial information were unaffected. [2]
Timeline
Public disclosure
Date TechCrunch published Substack’s confirmation and quoted the user notification.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Substack said it identified the issue in February 2026, fixed the problem, and began an investigation. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
