The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Substack confirmed unauthorized access to limited user data in October 2025, including email addresses, phone numbers and unspecified internal metadata. The company said passwords, credit-card numbers and other financial information were not accessed. A reported database containing 697,313 records may have appeared on BreachForums, but Substack has not confirmed that figure as the number of affected users.
The confirmed timeline
- An unauthorized party accessed Substack systems in October 2025.
- Substack said it became aware of the issue around February 3, 2026, and notified affected users that month.
- The company said it fixed the vulnerability and began an investigation. It also said it had no evidence the accessed data was being misused when users were notified.
These details come from Substack’s notification as reported by TechCrunch. The reporting establishes a real unauthorized-access incident, not merely an online rumor.
What information was exposed?
Substack’s stated categories
- Email addresses
- Phone numbers
- Other internal metadata, which Substack has not publicly defined
What Substack said was not accessed
- Passwords
- Credit-card numbers
- Other financial information
The available reporting does not establish that private posts, drafts, direct messages, subscription histories, authentication tokens or creator subscriber lists were exposed. “Internal metadata” should not be treated as proof that any of those fields were included.
Is the 697,313-user figure confirmed?
No. Engadget and other secondary coverage reported that a threat actor allegedly posted a database containing 697,313 records on BreachForums. Substack has not publicly confirmed that number, and it has not disclosed an official total of affected accounts.
#1 Best Overall
A database’s record count is not automatically a count of people. It could contain duplicate, historical, stale or malformed records, or data unrelated to the October incident. The careful wording is therefore: Substack confirmed a breach involving contact information; the nearly 700,000-record database and its connection to the incident remain unverified.
What risk does this create?
Email addresses and phone numbers are valuable for targeted phishing, spam and social engineering even when passwords and payment data are absent. Someone who knows that you use Substack could send messages posing as:
- A Substack security alert
- A subscription renewal, refund or payment request
- A publication invitation
- A phone-number verification prompt
- A link claiming to show the leaked database
A known phone number can also support scam calls, SMS phishing or attempts to persuade a mobile carrier or support desk to transfer a number. These are plausible risks, not evidence that these specific attacks have already occurred.
What Substack users should do now
- Verify any notification independently. Type Substack’s known web address into your browser or use a trusted bookmark instead of clicking an unexpected email or text link.
- Reject requests for secrets. Substack or another legitimate service should not require you to disclose a password, one-time authentication code or payment details through an unsolicited message.
- Use a unique password. Substack said passwords were not accessed, so a reset is not mandatory solely because of this incident. Change any password reused on other sites, especially your email password.
- Secure your email account. Turn on multifactor authentication and review recent sign-ins and account-recovery settings. Your email account often controls password resets for other services.
- Protect your mobile account. Where available, set an account PIN and enable your carrier’s port-out or number-transfer protection.
- Monitor messages and calls. Treat urgency, unexpected links, payment demands and requests for verification codes as warning signs. Report suspected fraud to the relevant service and your carrier.
- Check breach-monitoring services cautiously. A lookup may not include this incident or may lag behind public reporting, so a clean result does not prove you were unaffected.
Do not download or circulate the alleged database. A VPN cannot make an already exposed email address or phone number private, and canceling payment cards is not warranted by Substack’s statement that financial information was not accessed.
Recommended Free Tools
Additional steps for writers and publication owners
- Warn readers through an established publication or social channel, not a newly created “security” address.
- Do not export or redistribute subscriber data while investigating.
- Review publication administrators, integrations and third-party tools.
- Check whether payment or automation services reuse the same credentials.
- Explain that a creator cannot independently determine which readers were included in Substack’s incident.
- Watch for impersonation of the publication, its writers or its support staff.
Nothing in the available reporting confirms that publication content or subscriber lists were exposed.
What remains unknown
- The technical cause or vulnerability
- The attacker’s identity
- Whether the alleged 697,313-record database is authentic
- Whether it came entirely from the October access
- The number of unique affected users
- Whether every record belongs to an active account
- The exact meaning of “internal metadata”
- Whether private content, subscription history or creator-side information was included
- Whether the data remains publicly accessible
- Whether regulators or law enforcement are investigating
- Why detection took from October 2025 until early February 2026
Optional tools—and their limits
Free, sensible precautions should come first. Readers who want additional protection may consider:
Rank #4
| Tool type | Examples | Useful for | Limit |
|---|---|---|---|
| Password manager | 1Password, Bitwarden, Proton Pass | Creating and storing unique passwords | Cannot remove an exposed email address or phone number |
| Email aliases | Proton Pass aliases, SimpleLogin, IronVest | Compartmentalizing future newsletter signups | Cannot retroactively conceal an address already exposed; recovery forwarding must remain accessible |
| Breach monitoring | Have I Been Pwned, Google account-security tools, Aura, IdentityForce | Alerts about some known breach or identity activity | May omit this incident, arrive late or fail to cover phone-number exposure; paid services cannot guarantee removal or prevention |
A VPN is not a direct remedy for this breach. Current prices and plan terms for the listed commercial services are not established here.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Bottom line
The Substack breach is confirmed, but “nearly 700,000 users” is not. Treat 697,313 as an alleged database-record count, not a verified victim total. The practical response is to verify messages independently, secure your email and mobile accounts, use unique credentials and remain alert for phishing.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




