CSIDB logo
Incident

Substack

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:19

Linked entities

Victim
Substack
Threat actors
0 actors
Sources
7 sources

Timeline

Occurred
Oct 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In October 2025, an unauthorized third party exploited a system vulnerability to access limited user data from the newsletter platform, going undetected until February 2026 when the issue was identified. The compromised information included email addresses, phone numbers, and internal account metadata, while passwords, credit card numbers, and other financial data were not affected. A threat actor later claimed responsibility on a cybercrime forum, asserting that nearly 700,000 records were obtained through scraping, though Substack did not confirm this figure or specify the total number of affected users. The company stated that the underlying vulnerability has been fixed, additional safeguards implemented, and a full investigation launched, with no evidence so far of misuse of the exposed data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2025, an unauthorized third party gained access to limited user data from Substack, a newsletter and digital publishing platform used by writers, journalists, and creators. According to notifications sent by Substack CEO and cofounder Chris Best, the compromised information included user email addresses, phone numbers, and internal account metadata. Best stated that more sensitive data, including passwords, credit card numbers, and other financial information, was not accessed during the incident. Substack's email authentication system, which relies on "magic links" sent to users' registered email addresses rather than traditional passwords, was identified as the default access method, though legacy passwords for accounts created before 2023 could still exist. The platform reported having more than 50 million active subscriptions, including 5 million paid subscriptions, as of March 2025, and approximately 35 million subscribers according to separate reporting.

The breach was not discovered until February 3, 2026, when Substack's security team identified "evidence of a problem with our systems that allowed an unauthorized third party to access limited user data without permission." This detection occurred roughly four months after the initial unauthorized access in October 2025. Following the identification, Substack stated it fixed the system issue that allowed the unauthorized access and initiated a full investigation. On February 4, 2026, Best sent notification emails to affected users, beginning with the message, "I'm incredibly sorry this happened. We take our responsibility to protect your data and your privacy seriously, and we came up short here." The company stated that it did not have evidence that the compromised information was being misused but encouraged users to exercise caution with suspicious emails and text messages. A Substack spokesperson later told Infosecurity Magazine that the access occurred "during a short window" and that additional safeguards had been put in place once the issue was identified.

The incident came to broader public attention after a threat actor posted on a popular cybercrime forum claiming responsibility for the breach. The hacker alleged that nearly 700,000 records had been obtained through scraping and described the attack as "noisy," which reportedly led Substack to implement mitigations more rapidly. The claimed data fields included names, email addresses, phone numbers, profile pictures, user IDs, and bios. One dark web source cited by CSO Online reported the breach compromised 697,313 records, though this figure remained unconfirmed by Substack. That same source also claimed that IDs from the payment system Stripe, used by creators to receive subscription revenue, were compromised, a detail Substack did not address in its public statements. Substack did not publicly confirm the exact number of affected users, the specific nature of the system vulnerability, or why the breach went undetected for approximately four months.

The delayed detection raised immediate questions about Substack's monitoring and logging capabilities. Security professionals noted that the phrase "limited user data" used in the company communications was vague, particularly given that email addresses and phone numbers are sufficient for targeted phishing campaigns, SIM-swap attempts, and doxxing. The four-month dwell time between the October 2025 access and the February 2026 discovery meant that affected user data could have been consolidated, traded, or already exploited during that window before notifications were issued. Substack's privacy policy describes a wide range of data that could fall under "metadata" depending on site usage, including user IDs, profile pictures, biographies, and IP addresses, leaving the full scope of exposure uncertain. At the time of the initial public disclosure, Substack had not posted a web announcement about the breach and limited its outreach to email notifications to affected users, suggesting that only a subset of its user base was directly impacted.

In response to the incident, Substack implemented additional safeguards beyond fixing the specific system issue and pledged to take steps to improve its systems and processes to prevent similar occurrences. The company launched a full investigation and stated it could not share specifics about its security systems and processes for confidentiality reasons. Substack's previous known security incident occurred in 2020, when the platform accidentally exposed user email addresses by placing them in the "cc" field instead of the "bcc" field of an email sent regarding a policy update. That earlier incident was described as an operational error rather than an external breach, contrasting with the unauthorized third-party access that characterized the 2025-2026 event. Substack's reported business milestones in 2025 included raising $100 million in Series C funding in July 2025, led by BOND and The Chernin Group with participation from Andreessen Horowitz and other investors, indicating continued growth and platform expansion during the period in which the breach occurred.

Sources

Sources available to members: 7 sources.

CSIDB