[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2gh7xc4dzypyl":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":31,"seoTitle":32,"seoDescription":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"6a452308a20f867c8ba8e725","substack","Substack Data Breach","substack.com","2025-10-23T00:00:00.000Z","2026-02-06T23:33:22.000Z",null,"2026-07-03T09:42:56.697Z","2026-07-19T00:02:42.461Z","Third party breach","",[],663121,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30],"Email addresses","Phone numbers","\u003Cp>The Substack data breach was recorded with account registrations affecting the publishing platform in October 2025 and circulating more widely in February 2026. Email addresses were included in approximately 663,000 account records, and some records contained phone numbers. In the context of the platform, public profile elements such as publication names and biographies can also be associated with the user's digital identity, so the incident should not be considered merely as an email list.\u003C\u002Fp> \u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2> \u003Cp>The data types listed in this record are the Email addresses and Phone numbers fields. The fields for passwords, payment cards, or private message content are not listed. Nevertheless, on publishing platforms like Substack, an email address combined with the author or reader identity, publication name, interest, and subscription communication becomes valuable for targeted social engineering.\u003C\u002Fp> \u003Ch2>Publishing and Subscription Context\u003C\u002Fh2> \u003Cp>Substack users can receive many messages such as newsletters, subscriptions, publication updates, payments, comments, follows, and author communications. This normal flow can make fake publisher invitations, subscription renewals, payment issues, content removal, or account verification messages appear legitimate. Users should take action from the known account panel instead of clicking the link in the message.\u003C\u002Fp> \u003Ch2>Telephone, Author and Reader Risks\u003C\u002Fh2> \u003Cp>There is also a risk of SMS and calls for the subset containing phone numbers. Messages such as fake subscription renewal, payment error, verification code, or broadcast security warning may be sent. When the phone number, email, and broadcast ID are used together, communication that appears more personal to the user can be established. No verification code should be shared by phone or message.\u003C\u002Fp> \u003Cp>From the authors' perspective, risk is somewhat different from that of readers. A fake copyright notice, account suspension notice, payment provider update, or advertising collaboration offer can be sent to a publisher. These messages can become convincing when personalized with the publication name and publicly available profile information. In particular, payment settings and domain name forwarding should be carefully protected.\u003C\u002Fp> \u003Cp>From the readers' perspective, the risk is the use of their interests and subscription context in messages. A user can be targeted around a specific publication or topic. This becomes more significant in sensitive reading habits such as political, health, finance, or personal development. Even if only email and phone are classified as data, the platform context can increase the privacy impact.\u003C\u002Fp> \u003Ch2>Security Lessons for Institutions and Publishers\u003C\u002Fh2> \u003Cp>For institutions and independent publishers, the Substack phenomenon serves as a reminder of the security of subscription communications and profile data. Publishers should clearly specify to their readers through which channel payment, subscription, and account verification processes will be conducted. Users, on the other hand, should enable multi-factor authentication on their accounts, set up a recovery email, and check their session history.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Affected users should carefully evaluate subscription, payment, publication invitation, content removal, copyright, account verification, or author collaboration messages coming from Substack. Even if the password field is not listed, email and phone information are sufficient for targeted communication. If action is to be taken, the known login address should be used, not the link in the message.\u003C\u002Fp> \u003Ch2>Long-Term Publication Identity Risk\u003C\u002Fh2> \u003Cp>The publishing context in a Substack record can indicate which topics users are interested in or which content creators they interact with. Even if this relationship is not directly listed as a data class, it can be inferred from email and profile context. Users following publications on topics such as political, financial, health, or personal development may encounter more targeted messages.\u003C\u002Fp> \u003Cp>Payment settings for publishers, custom domain, and subscriber management are critical areas. A fake Substack message can target the publisher's revenue stream, reader list, or account access. Readers, on the other hand, may be directed to fake payment pages under the pretext of subscription renewal or access to exclusive content. For both groups, the transaction should be done from the known account panel instead of the link in the message.\u003C\u002Fp> \u003Cp>For users without a phone number, the risk is more about email and profile matching; for users with a phone number, SMS and call channels are added. This distinction is important. Users should not share the verification code regardless of which channel they are reached through and should verify payment requests through a separate channel.\u003C\u002Fp>","Substack Data Breach (663.1 Thousand Reported Records)","Substack Data Breach. 663.1 Thousand reported records are reported. Reported data: Email addresses, Phone numbers. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fsubstack_com.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"Substack","Publishing","United States"]