the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Substack Breach Exposes User Emails in October Hack

ArticlesNewsletters
ArticlesNewsletters
Enterprise/SaaS/security monitoring

Substack Breach Exposes User Emails in October Hack

Newsletter platform notifies users after unauthorized access exposed contact data

by The Tech Buzz

PUBLISHED: Thu, Feb 5, 2026, 11:45 AM UTC | UPDATED: Fri, Sep 4, 2026, 3:25 PM UTC

Add as a preferred source on Google
Substack Breach Exposes User Emails in October Hack

Substack is scrambling to contain fallout from a security breach that exposed user email addresses and phone numbers for months before detection. The newsletter platform discovered the unauthorized access on February 3rd, but the intrusion actually occurred back in October 2025, according to CEO Chris Best's disclosure email. While Substack insists passwords and payment data remain secure, the months-long gap between breach and detection raises serious questions about the company's security monitoring capabilities at a time when content platforms face mounting pressure to protect creator and subscriber data.

Substack just handed phishing scammers a potential goldmine. The newsletter platform started notifying users this week that a hacker accessed internal systems without authorization back in October 2025, exposing email addresses, phone numbers, and other metadata. But here's the kicker - Substack only discovered the breach on February 3rd, meaning the compromised data sat exposed for four months before anyone noticed.

"On February 3rd, we identified evidence of a problem with our systems that allowed an unauthorized third party to access limited user data without permission, including email addresses, phone numbers, and other internal metadata," CEO Chris Best wrote in an email to affected account holders. The admission reveals a troubling blind spot in Substack's security infrastructure at a critical moment for the company.

Substack has been positioning itself as the go-to platform for independent creators and journalists fleeing traditional media, but this breach exposes the kind of security gaps that could make writers think twice. The company now claims it's fixed the vulnerability and launched a full investigation, but it's offered zero technical details about what actually went wrong or how an intruder managed to lurk undetected for months.

Best tried to soften the blow by emphasizing what wasn't compromised. Passwords remain secure, credit card numbers are safe, and other financial information stayed locked down, according to the company. "We do not have evidence that this information is being misused, but we encourage you to take extra caution with any emails or text messages you receive that may be suspicious," Best added in the disclosure.

Advertisement

But that's cold comfort for users whose contact information is now potentially circulating in dark web marketplaces. Email addresses and phone numbers are the basic building blocks of sophisticated phishing campaigns and social engineering attacks. Hackers can use this data to craft convincing impersonation emails or SMS messages targeting Substack users, potentially tricking them into handing over passwords or payment details that weren't part of the original breach.

The scope of the breach remains murky. Substack hasn't disclosed how many users were affected, and the notification emails appear to have gone out selectively. Several reporters at The Verge who actively use Substack accounts confirmed they didn't receive breach notifications, suggesting either a targeted compromise or that Substack is still identifying affected users.

This incident lands at an awkward time for Substack, which has been fighting to maintain its position as the creator economy's newsletter darling. The platform faces mounting competition from Meta's newsletter initiatives, Twitter's revamped subscription features, and traditional email marketing tools adding creator-friendly features. A major security incident that took four months to detect doesn't exactly inspire confidence in creators who've built their entire businesses on the platform.

The four-month detection gap is perhaps the most damning detail in this entire saga. Modern security operations typically catch unauthorized access within hours or days through automated monitoring systems that flag unusual data queries or access patterns. That Substack apparently lacked the visibility to spot a breach for an entire third of a year suggests the company may have been operating with inadequate security logging or monitoring infrastructure.

Advertisement

"I'm incredibly sorry this happened," Best concluded in his email. "We take our responsibility to protect your data and your privacy seriously, and we came up short here." The company says it's now "bolstering its systems to prevent this type of issue from happening in the future," but hasn't provided specifics about what enhanced security measures it's implementing.

For affected users, the immediate risk isn't catastrophic - email addresses and phone numbers alone can't empty bank accounts. But this data becomes dangerous in the wrong hands when combined with social engineering tactics. Users should be especially wary of any emails or texts claiming to be from Substack asking them to verify account details, reset passwords, or click suspicious links. The real Substack will never ask for passwords via email.

Substack hasn't responded to requests for additional details about the breach's technical nature or total user impact. Until the company provides more transparency about what went wrong and how it plans to prevent future incidents, creators and subscribers are left wondering whether their newsletter platform takes security as seriously as it takes its 10% cut of subscription revenue.

The Substack breach underscores a harsh reality for SaaS platforms in the creator economy - security isn't just an IT problem, it's an existential business risk. When your entire value proposition depends on creators trusting you with their audience relationships, a four-month detection gap isn't just embarrassing, it's potentially business-threatening. Users should enable two-factor authentication if they haven't already, watch for phishing attempts, and consider whether they're comfortable building their business on a platform that took a third of a year to notice someone was rifling through user data. Substack needs to move fast with concrete security improvements and full transparency if it wants to keep creators from eyeing the exits.

More Topics:
security monitoring

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

Email addresses, phone numbers, and internal metadata were exposed in the October 2025 Substack breach discovered February 3rd, 2026. Passwords, credit cards, and financial information were not compromised. The breach affected an undisclosed number of users.

Substack discovered the security breach on February 3rd, 2026. The unauthorized access actually occurred in October 2025, representing a four-month detection gap. CEO Chris Best notified affected users through email disclosure.

Yes, Substack confirmed passwords were not compromised in the breach. Credit cards and financial information also remain secure. However, exposed email addresses and phone numbers could be used for phishing attacks, so monitor for suspicious messages.

Enable two-factor authentication on your Substack account immediately. Watch for suspicious emails or texts claiming to be from Substack asking for passwords. The real Substack never requests passwords via email. Monitor for phishing attempts and social engineering attacks.

Substack likely lacked adequate security monitoring infrastructure. Modern security operations detect unauthorized access within hours or days using automated systems. The four-month detection gap suggests significant vulnerabilities in Substack's security logging and monitoring capabilities.

Evaluate based on your risk tolerance and Substack's security improvements. The breach exposed contact information for phishing but not financial data. Consider whether you trust their enhanced security measures and whether alternative creator platforms better suit your needs.

More in Enterprise/SaaS

Adobe Taps Anil Chakravarthy to Replace Narayen as CEO

Adobe Taps Anil Chakravarthy to Replace Narayen as CEO

Zscaler Beats Estimates, Bets Big on Agentic AI

Australia's Data Centre Boom Sparks Resource Fight

Australia's Data Centre Boom Sparks Resource Fight

Google Adds Voice Commands to Gmail, Docs, Keep

Google Adds Voice Commands to Gmail, Docs, Keep

Palo Alto Networks Buys Console for $500M

Palo Alto Networks Buys Console for $500M

Microsoft to Finally Reveal Azure's Real Dollar Revenue

Microsoft to Finally Reveal Azure's Real Dollar Revenue

More Articles

Snowflake Stock Jumps 22% on AI Coding Agent Boost

Snowflake Stock Jumps 22% on AI Coding Agent Boost

Sep 2

150M Driver's License Photos Allegedly Stolen

150M Driver's License Photos Allegedly Stolen

Sep 2

Palo Alto CEO: AI Exposes $1T Security Gap

Palo Alto CEO: AI Exposes $1T Security Gap

Sep 2

Palo Alto CEO: $1T in Cyber Infrastructure Not AI-Ready

Palo Alto CEO: $1T in Cyber Infrastructure Not AI-Ready

Sep 2

Palo Alto Networks Stock Soars on AI Security Boom

Palo Alto Networks Stock Soars on AI Security Boom

Sep 1

Dell Stock Jumps 9% as AI Server Sales Forecast Triples

Dell Stock Jumps 9% as AI Server Sales Forecast Triples

Sep 1