October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Substack Breach Exposed Emails and Phone Numbers—But the Nearly 700,000-User Figure Is Unconfirmed

Substack confirmed unauthorized access to email addresses, phone numbers and internal metadata, but has not verified the alleged 697,313-record database as its victim count.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Substack confirmed unauthorized access to limited user data in October 2025, including email addresses, phone numbers and unspecified internal metadata. The company said passwords, credit-card numbers and other financial information were not accessed. A reported database containing 697,313 records may have appeared on BreachForums, but Substack has not confirmed that figure as the number of affected users.

The confirmed timeline

  1. An unauthorized party accessed Substack systems in October 2025.
  2. Substack said it became aware of the issue around February 3, 2026, and notified affected users that month.
  3. The company said it fixed the vulnerability and began an investigation. It also said it had no evidence the accessed data was being misused when users were notified.

These details come from Substack’s notification as reported by TechCrunch. The reporting establishes a real unauthorized-access incident, not merely an online rumor.

What information was exposed?

Substack’s stated categories

  • Email addresses
  • Phone numbers
  • Other internal metadata, which Substack has not publicly defined

What Substack said was not accessed

  • Passwords
  • Credit-card numbers
  • Other financial information

The available reporting does not establish that private posts, drafts, direct messages, subscription histories, authentication tokens or creator subscriber lists were exposed. “Internal metadata” should not be treated as proof that any of those fields were included.

Is the 697,313-user figure confirmed?

No. Engadget and other secondary coverage reported that a threat actor allegedly posted a database containing 697,313 records on BreachForums. Substack has not publicly confirmed that number, and it has not disclosed an official total of affected accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A database’s record count is not automatically a count of people. It could contain duplicate, historical, stale or malformed records, or data unrelated to the October incident. The careful wording is therefore: Substack confirmed a breach involving contact information; the nearly 700,000-record database and its connection to the incident remain unverified.

What risk does this create?

Email addresses and phone numbers are valuable for targeted phishing, spam and social engineering even when passwords and payment data are absent. Someone who knows that you use Substack could send messages posing as:

  • A Substack security alert
  • A subscription renewal, refund or payment request
  • A publication invitation
  • A phone-number verification prompt
  • A link claiming to show the leaked database

A known phone number can also support scam calls, SMS phishing or attempts to persuade a mobile carrier or support desk to transfer a number. These are plausible risks, not evidence that these specific attacks have already occurred.

What Substack users should do now

  1. Verify any notification independently. Type Substack’s known web address into your browser or use a trusted bookmark instead of clicking an unexpected email or text link.
  2. Reject requests for secrets. Substack or another legitimate service should not require you to disclose a password, one-time authentication code or payment details through an unsolicited message.
  3. Use a unique password. Substack said passwords were not accessed, so a reset is not mandatory solely because of this incident. Change any password reused on other sites, especially your email password.
  4. Secure your email account. Turn on multifactor authentication and review recent sign-ins and account-recovery settings. Your email account often controls password resets for other services.
  5. Protect your mobile account. Where available, set an account PIN and enable your carrier’s port-out or number-transfer protection.
  6. Monitor messages and calls. Treat urgency, unexpected links, payment demands and requests for verification codes as warning signs. Report suspected fraud to the relevant service and your carrier.
  7. Check breach-monitoring services cautiously. A lookup may not include this incident or may lag behind public reporting, so a clean result does not prove you were unaffected.

Do not download or circulate the alleged database. A VPN cannot make an already exposed email address or phone number private, and canceling payment cards is not warranted by Substack’s statement that financial information was not accessed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Additional steps for writers and publication owners

  • Warn readers through an established publication or social channel, not a newly created “security” address.
  • Do not export or redistribute subscriber data while investigating.
  • Review publication administrators, integrations and third-party tools.
  • Check whether payment or automation services reuse the same credentials.
  • Explain that a creator cannot independently determine which readers were included in Substack’s incident.
  • Watch for impersonation of the publication, its writers or its support staff.

Nothing in the available reporting confirms that publication content or subscriber lists were exposed.

What remains unknown

  • The technical cause or vulnerability
  • The attacker’s identity
  • Whether the alleged 697,313-record database is authentic
  • Whether it came entirely from the October access
  • The number of unique affected users
  • Whether every record belongs to an active account
  • The exact meaning of “internal metadata”
  • Whether private content, subscription history or creator-side information was included
  • Whether the data remains publicly accessible
  • Whether regulators or law enforcement are investigating
  • Why detection took from October 2025 until early February 2026

Optional tools—and their limits

Free, sensible precautions should come first. Readers who want additional protection may consider:

Tool type Examples Useful for Limit
Password manager 1Password, Bitwarden, Proton Pass Creating and storing unique passwords Cannot remove an exposed email address or phone number
Email aliases Proton Pass aliases, SimpleLogin, IronVest Compartmentalizing future newsletter signups Cannot retroactively conceal an address already exposed; recovery forwarding must remain accessible
Breach monitoring Have I Been Pwned, Google account-security tools, Aura, IdentityForce Alerts about some known breach or identity activity May omit this incident, arrive late or fail to cover phone-number exposure; paid services cannot guarantee removal or prevention

A VPN is not a direct remedy for this breach. Current prices and plan terms for the listed commercial services are not established here.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Bottom line

The Substack breach is confirmed, but “nearly 700,000 users” is not. Treat 697,313 as an alleged database-record count, not a verified victim total. The practical response is to verify messages independently, secure your email and mobile accounts, use unique credentials and remain alert for phishing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.