Substack Data Breach Confirmed: User Phone Numbers and Email Addresses Were All Stolen in Attack, Here’s What We Know


  • Substack confirms October 2025 breach exposing user emails, phone numbers and metadata
  • CEO Chris Best assured that no financial data or identifying information was accessed; hole repaired and investigation underway
  • BreachForums thread claims around 700,000 records stolen, although Substack claims no evidence of abuse so far

Substack has confirmed that malicious actors have broken into its systems and stolen users’ emails and phone numbers.

On social media, people are sharing screenshots of a data breach notification letter, sent to affected individuals by Substack CEO Chris Best, claiming the company found “evidence of an issue with our systems” on February 3. This issue allowed an unidentified and unauthorized third party “to gain unauthorized access to limited user data, including email addresses, phone numbers, and other internal metadata.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top