Summary
Key Points:
- Substack experienced a data breach affecting user email addresses and phone numbers, potentially compromising 697,313 records.
- The breach, discovered in February 2026 but occurring in October 2025, did not expose passwords or financial information, yet raises concerns about user privacy due to the nature of the leaked metadata.
- Users are advised to remain vigilant against suspicious emails and consider enabling multi-factor authentication if not already in use.
Technical Details: The breach exploited an unspecified vulnerability in Substack's systems, leading to unauthorized access to user data. While no credit card or password information was compromised, the leaked metadata may include sensitive identifiers.
MITRE ATT&CK Techniques: None mentioned
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.