---
title: "Substack user contact-data incident"
description: "Evidence-backed account of Substack user contact-data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/substack-user-contact-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/substack-user-contact-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/substack-user-contact-data-incident-2025/stix.json"
---

# Substack user contact-data incident

Unauthorized access to limited Substack user data, identified and disclosed in February 2026. Company-confirmed email, phone, and internal-metadata exposure with a separately measured HIBP corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to limited [Substack](https://substack.com/) user data, identified and disclosed in February 2026. [2](#source-2)

## Impact

Company-confirmed email, phone, and internal-metadata exposure with a separately measured HIBP corpus. [1](#source-1) [2](#source-2)

Documented data types include:

- Contact information — Email addresses and phone numbers confirmed by Substack; only a subset of HIBP corpus records contained phone numbers. [1](#source-1) [2](#source-2)

A cited record reports 663,121 records (Unique email addresses represented in HIBP's verified corpus; not a Substack-confirmed count of people, account holders, subscriptions, accounts, or total rows; as of 2026-02-06). [1](#source-1) [2](#source-2)

Substack said it had no evidence that user data was being misused and advised users to be cautious with emails and texts. [2](#source-2)

Substack said other unspecified internal metadata was accessed; HIBP described public profile information such as publication names and bios in its corpus. [1](#source-1) [2](#source-2)

Substack said an unauthorized third party accessed limited user data without permission after an issue allowed access to parts of its systems. [2](#source-2)

Substack said credit-card numbers, passwords, and other financial information were unaffected. [2](#source-2)

## Timeline

### October 23, 2025 — Documented event

HIBP BreachDate; Substack said the unauthorized access occurred in October 2025 but did not publicly confirm the exact day in the preserved company email. [1](#source-1) [2](#source-2)

### February 5, 2026 — Public disclosure

Date TechCrunch published Substack's confirmation and quoted the user notification. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Substack said it identified the issue in February 2026, fixed the problem, and began an investigation. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/substack-user-contact-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Substack breach record

advisory · Have I Been Pwned · Feb 6, 2026

<https://haveibeenpwned.com/api/v3/breach/Substack>

<a id="source-2"></a>

### Substack confirms data breach affects users' email addresses and phone numbers

news · TechCrunch · Feb 5, 2026

<https://techcrunch.com/2026/02/05/substack-confirms-data-breach-affecting-email-addresses-and-phone-numbers/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Occurred At · 80% confidence · current**  
   October 2025 Substack unauthorized-access incident: 2025-10-23
2. **Exposed Record Count · 100% confidence · current**  
   Substack user contact and profile-metadata exposure: 663,121 record
3. **Affected Organization · 100% confidence · current**  
   October 2025 Substack unauthorized-access incident: Substack, Inc.
4. **Resulted In · 100% confidence · current**  
   October 2025 Substack unauthorized-access incident: Substack said it had no evidence that user data was being misused and advised users to be cautious with emails and texts.
5. **Disclosed At · 100% confidence · current**  
   October 2025 Substack unauthorized-access incident: 2026-02-05
6. **Resulted In · 90% confidence · current**  
   Substack user contact and profile-metadata exposure: Substack said other unspecified internal metadata was accessed; HIBP described public profile information such as publication names and bios in its corpus.
7. **Resulted In · 100% confidence · current**  
   October 2025 Substack unauthorized-access incident: Substack said an unauthorized third party accessed limited user data without permission after an issue allowed access to parts of its systems.
8. **Resulted In · 100% confidence · current**  
   October 2025 Substack unauthorized-access incident: Substack said it identified the issue in February 2026, fixed the problem, and began an investigation.
9. **Resulted In · 100% confidence · current**  
   Substack user contact and profile-metadata exposure: Substack said credit-card numbers, passwords, and other financial information were unaffected.
10. **Resulted In · 100% confidence · current**  
   October 2025 Substack unauthorized-access incident: Substack user contact and profile-metadata exposure
11. **Exposed Data Category · 100% confidence · current**  
   Substack user contact and profile-metadata exposure: Contact information

</details>
