Why there is no official statement from Substack about the data leak

Published: (February 7, 2026 at 11:34 PM EST)
2 min read

Source: Hacker News

Overview

Newsletter platform Substack confirmed a data breach in an email to users. In October, an “unauthorized third party” accessed user data, including email addresses, phone numbers, and other unspecified internal metadata. More sensitive data—such as credit card numbers, passwords, and other financial information—was unaffected.

Details of the breach

  • Date of incident: October (unauthorized access)
  • Discovery: February, when Substack identified the issue that allowed someone to access its systems.
  • Data accessed: Email addresses, phone numbers, and internal metadata. No evidence that credit‑card numbers, passwords, or other financial information were compromised.

The exact nature of the system vulnerability and the full scope of the accessed data remain unclear. It is also unknown why the breach went undetected for five months or whether the attackers demanded a ransom.

Company response

Substack’s chief executive, Chris Best, sent an email to users stating:

“I’m reaching out to let you know about a security incident that resulted in the email address and phone number from your Substack account being shared without your permission. I’m incredibly sorry this happened. We take our responsibility to protect your data and your privacy seriously, and we came up short here.”

Key points from the response:

  • The issue has been fixed, and an investigation is underway.
  • Substack has no evidence that the compromised data is being misused.
  • Users were advised to exercise caution with emails and texts, though no specific indicators were provided.

Impact and next steps

  • Number of affected users: Not disclosed.
  • Evidence of abuse: Substack reported no signs of misuse but did not detail the technical methods (e.g., log analysis) used to reach this conclusion.
  • User guidance: General caution advised; no concrete remediation steps were outlined.

TechCrunch has reached out for additional details and will update the story if more information becomes available.

Background on Substack

  • Substack reports more than 50 million active subscriptions, including 5 million paid subscriptions—a milestone it reached last March (source).
  • In July 2025, the company raised $100 million in Series C funding led by BOND and The Chernin Group, with participation from a16z, Klutch Sports Group CEO Rich Paul, and Skims co‑founder Jens Grede (TechCrunch article).
0 views
Back to Blog

Related posts

Read more »

과기정통부, “쿠팡 3000건 유출 주장은 신뢰도 떨어져” 정면 반박

배경훈 부총리 겸 과학기술정보통신부 장관은 2월 11일 국회 과학기술정보방송통신위원회 과기정통부 업무보고에서 쿠팡이 개인정보 유출 사고와 관련해 언급한 “약 3000건 유출” 주장에 대해 “신뢰도가 떨어진다”고 반박했다. 이는 전날2월 10일 정부·민관합동조사단이 발표한 “3367만 3...

쿠팡 3367만건 고객정보 유출 공식 확인

!https://cdn.byline.network/wp-content/uploads/2026/02/COOPANG1112.jpg 개요 쿠팡 전 직원이 무단으로 고객 개인정보 33,673,817건을 유출하고, 배송지 정보 약 1억 4,800만 회를 조회한 사실이 정부 조사를 통해 확인되었습...