Substack Data Breach Exposes User Emails and Phone Numbers
Substack has officially confirmed a security incident involving unauthorized access to its platform. In a communication sent to its user base, the newsletter service revealed that an external party gained entry to its systems, compromising specific personal information belonging to its subscribers.

Scope of the Security Incident
According to the company, the breach allowed an unauthorized third party to access user email addresses, phone numbers, and various forms of internal metadata. Despite the unauthorized access, Substack clarified that highly sensitive information, including user passwords, credit card details, and other financial records, was not compromised during the event.
The company identified the vulnerability in February, which reportedly allowed the unauthorized access to take place back in October. While the platform claims to have resolved the underlying technical issue and launched an internal investigation, it has yet to disclose the exact number of affected users or provide clarity on why the detection of the breach took five months.
Response from Leadership
Chris Best, CEO of Substack, addressed the incident directly in an email to the platform’s community. “I’m reaching out to let you know about a security incident that resulted in the email address and phone number from your Substack account being shared without your permission,” Best stated. He added, “I’m incredibly sorry this happened. We take our responsibility to protect your data and your privacy seriously, and we came up short here.”
Data Security and User Guidance
Although the company maintains there is currently no evidence that the stolen data is being actively misused, it has not specified the monitoring methods or logs used to reach this conclusion. As a precaution, Substack is advising its users to exercise heightened caution regarding unsolicited emails and text messages.
The scale of the platform is significant, with Substack reporting over 50 million active subscriptions, including 5 million paid plans, a milestone reached in March of last year. The company, which reached this milestone following a history of substantial venture capital backing, continues to face scrutiny over its data handling practices following this disclosure.