Substack is notifying some users that the email addresses and phone numbers associated with their accounts were exposed in a “security incident” last year. In an email to account holders, Substack CEO Chris Bestsaid that a hacker had gained unauthorized access to internal data in October 2025, but that passwords, credit card numbers, and other financial information remain secure.
See also: Leak of photos from private Instagram profiles

“On February 3, we identified evidence of an issue with our systems that allowed an unauthorized third party to access restricted user data without permission, including email addresses, phone numbers, and other internal metadata,” Best said in the email. “We have no evidence that this information is being misused, but we encourage you to be extra cautious with any emails or text messages you receive that may be suspicious.”
Substack says it has fixed the security issue and is conducting a full investigation, while strengthening its systems “to prevent this type of issue from occurring in the future.” The platform did not provide details on what the security issue was or how many users were affected.
See also: France: Free Mobile fined for 2024 data breach

The data breach is a serious blow to the platform, which has gained popularity as a tool for content creators looking to maintain direct communication with their audiences. The breach comes at a time when data security is more critical than ever, and users expect platforms to take strict measures to protect their personal information.
Substack, like many other platforms, is constantly facing cybersecurity challenges. Protecting user data is a top priority, and companies need to invest in technologies and processes that will prevent such breaches in the future. Transparency and direct communication with users are also critical, as they help maintain trust and credibility.
See also: Hacker jailed for breaching Rotterdam and Antwerp ports

Substack is committed to keeping its users informed of any developments regarding the incident and to taking all necessary measures to restore data security. Users are urged to be vigilant and report any suspicious activity that may be related to their personal data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
