Skip to main content
Back to overview
Medium

Substack Discloses Security Incident After Hacker Leaks Data

Substack discovered a security incident on February 3, 2026, where an unauthorized third party accessed limited user data in October 2025.

Key points

  • Discovered on February 3, 2026.
  • Unauthorized access occurred in October 2025.
  • Approximately 697,000 user records leaked.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social, Hacking activity

03

Potential impact

Data Exposure

Confidentiality

Published
Feb 3, 2026
Updated
Jun 25, 2026
Confidence
Medium
Evidence
4 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

SubstackData DisclosureSubstackDiscoveredUnauthorizedApproximately

Quick context

Questions about this signal

What happened in this signal?

Substack discovered a security incident on February 3, 2026, where an unauthorized third party accessed limited user data in October 2025. The breach exposed email addresses, phone numbers, and internal metadata for approximately 697,000 users. Substack confirmed that no passwords, credit card numbers, or financial information were compromised. The company has since fixed the vulnerability and is investigating the incident, while warning users to be vigilant against potential phishing attempts.

When was this signal reported?

Shadow Tier lists Feb 3, 2026 as the signal date.

Which organization is connected to this signal?

Substack is the organization connected to this public signal.

Explore Substack
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence