Substack notifies users about a “limited” data breach in October 2025 via a now-patched flaw found on February 3; a threat actor leaked a ~697K-record database
Newsletter platform Substack is notifying users of a data breach after attackers stole their email addresses and phone numbers in October 2025.
Context & Ripple Effects
The incident puts a newsletter platform alongside other communications services whose contact data has become a valuable target. A prior Mailchimp audience-data breach was followed by phishing aimed at crypto users, illustrating why email-address exposure can matter beyond the initial intrusion.
It also resembles the account-discovery flaw Twitter said linked users’ phone numbers and emails to accounts, a patched bug exploited to map contact details to users. The common risk is not necessarily password theft, but the creation of usable identity and outreach lists.
First-order effects
- Substack is notifying affected users and has patched the flaw; roughly 697,000 leaked records containing email addresses and phone numbers are now outside the platform’s control.
- Affected users face a higher near-term risk of convincing phishing, spam, or unwanted contact using the exposed details, especially messages impersonating Substack or newsletter operators.
Second-order effects
- Newsletter writers and publishers may need to warn audiences about impersonation attempts, since attackers can use a platform-associated contact list to make outreach appear credible.
- The disclosure increases pressure on Substack to show that the patch and user-notification process adequately contain the issue; competing newsletter services can emphasize account and contact-data protections.
Third-order effects
- If contact-data leaks continue across creator and communications platforms, security of subscriber identity data will become more central to trust in subscription-based publishing, not merely a back-office compliance concern.
- The recurring pattern of patched flaws followed by leaked datasets favors stronger controls around data access and account discovery, though the available coverage does not establish whether this incident reflects a broader shared technical weakness.
The trend: Creator and communications platforms are increasingly being judged on how well they protect the contact data that underpins their audience relationships.