Skip to main content

Company intelligence

Substack cybersecurity incidents and threat signals

substack.com

Substack logo

This company page brings together public reporting currently associated with Substack. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

June 25, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Substack. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Substack

Substack logoPhishing
Medium

Substack Discloses Security Incident After Hacker Leaks Data

Substack discovered a security incident on February 3, 2026, where an unauthorized third party accessed limited user data in October 2025. The breach exposed email addresses, phone numbers, and internal metadata for approximately 697,000 users. Substack confirmed that no passwords, credit card numbers, or financial information were compromised. The company has since fixed the vulnerability and is investigating the incident, while warning users to be vigilant against potential phishing attempts.

Substack

FAQ

Questions about Substack cybersecurity reporting

What does the Substack page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Substack.

Does every mention of Substack appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.