Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposureunderground-data-leakbreach-disclosure-notificationphishing-campaign-intelligence

Substack Data Breach Exposes User Email Addresses and Phone Numbers

Updated 3mo agoFirst seen Feb 5, 20267 sources

Substack confirmed an incident in which an unauthorized third party accessed limited user data, including email addresses, phone numbers, and other unspecified internal metadata. The company said the access occurred in October 2025 and that passwords, credit card numbers, and other financial information were not accessed; CEO Chris Best stated Substack identified evidence of the issue in early February and has since fixed the underlying problem and opened an investigation.

Public reporting indicates the breach may be connected to data posted on criminal forums: a threat actor allegedly leaked a database on BreachForums containing 697,313 records and claimed the data was obtained via a “noisy” scraping method that was quickly patched. Substack has not disclosed the number of affected users or the precise technical root cause, and both reports note the company advised users to be cautious about phishing attempts leveraging the exposed contact details.

Share:
Substack Data Breach Exposes User Email Addresses and Phone Numbers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 18, 20263mo ago

Have I Been Pwned adds the Substack breach

Have I Been Pwned published an entry for the Substack breach, describing about 663,000 affected account records from the October 2025 incident and noting the data was more broadly circulated in February 2026. The listing said the exposed data included email addresses, public profile information, and phone numbers for a subset of users.

Feb 5, 20265mo ago

Substack notifies users and publicly confirms the data breach

On February 5, 2026, Substack confirmed the breach in notifications to users and public statements from CEO Chris Best. The company warned affected users to watch for phishing and suspicious emails or texts, and said it was taking steps to improve security controls and processes.

Feb 3, 20265mo ago

Substack identifies evidence of the breach and patches the issue

Substack said it discovered evidence of the incident on February 3, 2026, identified the underlying system issue, fixed or patched it, and began an internal investigation. The company later said it had no evidence of active misuse at that time.

Feb 2, 20265mo ago

Threat actor advertises alleged Substack dataset on BreachForums

On February 2, 2026, a threat actor posted or advertised an alleged Substack dataset on BreachForums, claiming to have obtained roughly 663,000 to nearly 700,000 user records. Reports said the data included contact details and other account-related fields.

Oct 1, 20259mo ago

Unauthorized access to Substack user data occurs

Substack said an unauthorized third party accessed limited user data in October 2025. The exposed information included email addresses, phone numbers, and internal account metadata, while passwords and financial or payment data were reportedly not accessed.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Affected products
2 linked
StripeTelegram
Organizations
11 linked
SubstackStripeHackReadThe RegisterTechCrunchHackread.comAndreessen HorowitzBONDThe Chernin GroupKlutch Sports GroupSkims
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.