LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Substack Data Breach (2025)

MEDIUM severityConfirmedHow we verify

Substack Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·October 23, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Substack Data Breach (2025)

Reported October 23, 2025. Approximately 663K people affected.

MEDIUM
Severity
663K
People affected
2
Data types exposed
October 23, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Substack disclosed a data breach on October 23, 2025, affecting 663,000 users whose email addresses and phone numbers were exposed. Check whether your account was involved and consider updating your contact details or enabling additional safeguards.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Substack Data Breach (2025) breach?
663K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Data breaches involving online publishing and subscription platforms have become a recurring feature of the modern threat landscape, where large collections of user contact details and profile information are frequently exposed and later redistributed. In this environment, even partial account records can enable phishing, account takeover attempts, and unwanted contact long after the initial incident. The Substack matter reported in late 2025 fits this pattern: a sizable set of account-holder records left the platform’s control and later circulated more widely, raising practical questions for writers, readers, and subscribers who rely on the service.

Public reporting indicates that Substack, the newsletter and publishing platform, experienced a data breach in October 2025 that exposed roughly 663,000 account-holder records. Those records included email addresses and publicly visible profile information such as publication names and bios; a subset also contained phone numbers. The material was subsequently circulated more widely in February 2026. Exact technical details of how the data left the organisation remain limited in public accounts, yet the scale and the nature of the fields involved make the incident consequential for anyone whose Substack account details may have been included.

What happened

According to available reporting, Substack suffered a data breach in October 2025. The incident was reported on 23 October 2025 and involved approximately 663,000 account-holder records. Those records contained email addresses together with publicly visible profile information drawn from Substack accounts, including publication names and bios. A subset of the records also included phone numbers. Public accounts state that the material was later circulated more widely in February 2026. No further Reported Details have been released regarding the precise method of compromise, the full duration of unauthorised access, or whether additional data categories beyond those named were involved. Attribution to any specific threat actor has not been established in the facts available for this summary.

How a breach like this happens

Incidents that result in the exposure of account-holder contact and profile data typically follow a small number of well-understood pathways. Attackers may obtain credentials through phishing or credential-stuffing campaigns that reuse passwords leaked from other services. They may exploit unpatched software vulnerabilities, misconfigured cloud storage, or weak access controls on administrative interfaces. Once inside a system, an adversary can often extract bulk records of user email addresses, associated profile fields, and any secondary contact details that the platform stores. In many cases the stolen data is later packaged and redistributed on criminal forums or leak sites months after the initial intrusion, which matches the timeline described for this matter—initial breach in October 2025 followed by wider circulation in February 2026. None of these general mechanisms has been confirmed as the cause of the Substack incident; they simply illustrate how comparable exposures commonly occur.

Who is Substack?

Substack is a publishing platform that enables writers, journalists, and organisations to create and distribute newsletters and other subscription-based content directly to readers. Users create accounts that typically include an email address for login and delivery, optional profile information such as a publication name and bio, and, in some cases, a phone number for verification or account recovery. The platform sits at the intersection of media, independent publishing, and subscription commerce; it therefore holds contact and identity-linked data for both content creators and their audiences. A breach affecting hundreds of thousands of such records is consequential because the same email addresses and profile details that facilitate legitimate newsletter delivery can also be used by third parties for unsolicited messaging, social-engineering attempts, or correlation with other leaked datasets.

What data was at risk

The facts identify the exposed data types as email addresses and, for a subset of records, phone numbers. The same records also contained publicly visible profile information from Substack accounts, specifically publication names and bios. No other categories—such as payment-card numbers, full physical addresses, passwords, or private message content—are named in the available reporting. Organisations of this type ordinarily store additional account metadata, subscription preferences, and authentication tokens, yet the precise contents of the full dataset beyond the fields listed remain unconfirmed. Readers should therefore treat only the named elements as established and regard any further assumptions as speculative.

Why it matters

For affected individuals the primary risks are practical rather than catastrophic. Email addresses can be used to craft convincing phishing messages that impersonate Substack or related services, potentially leading to further credential theft or malware delivery. Phone numbers, where present, open additional channels for smishing or voice-based social engineering. Publicly visible profile details such as publication names and bios can help an attacker personalise those approaches, increasing the chance that a recipient will engage. For the organisation, the incident creates operational and reputational costs: the need to notify users, review access controls, and maintain trust among writers and readers who depend on the platform for their livelihoods and information. Because the data was later circulated more widely, the window of potential misuse extends well beyond the original October 2025 timeframe. None of these outcomes is inevitable for every individual, yet the combination of volume and data types makes sustained vigilance warranted.

Were you affected?

If you maintain a Substack account, treat the possibility of exposure as real until you can verify otherwise. Begin by changing your Substack password and enabling any available multi-factor authentication. Review recent account activity for unfamiliar logins or subscription changes. Be especially cautious of unsolicited emails or text messages that reference your publication name, bio, or newsletter; verify any such contact through official channels rather than links supplied in the message. Monitor your email and phone for unusual activity in the coming months. As a further practical step, you can run a free exposure scan of your email address to check whether it has already appeared in known breach datasets; doing so provides an independent signal that can guide additional protective measures such as password resets on other services that share the same address.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanySubstack security record
70/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Substack’s full breach history →

More recent breaches

Pass'Sport Data Breach (2025)December 17, 2025APOIA.se Data Breach (2025)December 16, 2025SoundCloud Data Breach (2025)December 15, 2025Under Armour Data Breach (2025)November 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Substack Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram