Substack Data Breach Exposes User Phone Numbers and Emails

Share via:

Substack has confirmed a data breach that exposed phone numbers and email addresses of some users, raising fresh concerns about privacy and security in the rapidly growing creator economy.

Newsletter platform Substack has confirmed a data breach that resulted in the exposure of user phone numbers and email addresses, sending shockwaves through the creator economy and renewing scrutiny of how digital publishing platforms safeguard personal data.

The breach, disclosed after internal investigation, affected a subset of users including newsletter creators and subscribers. While Substack emphasized that no payment details or passwords were compromised, the exposure of direct contact information is significant—particularly for creators whose livelihoods depend on trust and audience relationships.

What happened?

According to Substack, unauthorized access allowed attackers to view certain user records containing email addresses and phone numbers. The company did not specify the exact number of users affected, but acknowledged that the breach stemmed from a third-party system vulnerability rather than its core publishing infrastructure.

Substack says it has since secured the affected systems, notified impacted users, and reported the incident to relevant regulators.

Why phone numbers matter more than passwords

While passwords can be changed, phone numbers and email addresses are permanent identifiers. Cybersecurity experts warn that such data can be exploited for phishing, SIM-swap attacks, targeted harassment, and identity correlation across platforms.

For independent journalists, activists, and niche creators—many of whom use Substack precisely to avoid platform dependency—this exposure raises serious safety and reputational risks.

Creator economy under pressure

Substack has positioned itself as a creator-first alternative to social media, emphasizing independence, ownership, and direct audience relationships. That positioning makes security incidents particularly damaging.

Unlike mass-market platforms, Substack hosts sensitive newsletters covering politics, finance, healthcare, and personal narratives. In some regions, disclosure of contact details could carry real-world consequences.

Substack’s response

https://substackcdn.com/image/fetch/%24s_%21rk0j%21%2Cf_auto%2Cq_auto%3Agood%2Cfl_progressive%3Asteep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ba3019e-295e-4833-aee8-750d0556c3ea_1418x816.gif

The company stated it is enhancing internal monitoring, auditing third-party integrations, and accelerating its security roadmap. Substack also reiterated that it does not sell user data and that the breach did not involve content access.

However, the lack of precise numbers and limited technical detail has drawn criticism from privacy advocates calling for greater transparency.

A broader industry problem

The incident reflects a wider challenge across SaaS and creator platforms: rapid growth often outpaces security maturity. As newsletter platforms expand monetization features—payments, analytics, SMS alerts—the volume of sensitive data they handle increases dramatically.

Regulators in the US and EU are increasingly scrutinizing how platforms disclose breaches and manage user consent.

What users should do now

Security professionals advise affected users to:

  • Be cautious of unsolicited emails or messages
  • Enable two-factor authentication where available
  • Monitor for phishing attempts referencing Substack activity
  • Avoid reusing email-linked credentials elsewhere

The trust test ahead

For Substack, the breach represents a critical trust test. The platform’s success depends not just on tools, but on creators’ confidence that their independence does not come at the cost of security.

As the creator economy professionalizes, privacy expectations will only rise.

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Editorial Team
StartupNews.fyi is a leading global startup and technology media platform known for its end-to-end coverage of the startup ecosystem across India and key international markets. Launched with the vision of becoming a single gateway for founders, investors, and ecosystem enablers, StartupNews.fyi has grown steadily over the years by publishing tens of thousands of verified news stories, insights, and ecosystem updates, reaching millions of startup enthusiasts every month through its digital platforms and communities.

Popular

More Like this

Substack Data Breach Exposes User Phone Numbers and Emails

Substack has confirmed a data breach that exposed phone numbers and email addresses of some users, raising fresh concerns about privacy and security in the rapidly growing creator economy.

Newsletter platform Substack has confirmed a data breach that resulted in the exposure of user phone numbers and email addresses, sending shockwaves through the creator economy and renewing scrutiny of how digital publishing platforms safeguard personal data.

The breach, disclosed after internal investigation, affected a subset of users including newsletter creators and subscribers. While Substack emphasized that no payment details or passwords were compromised, the exposure of direct contact information is significant—particularly for creators whose livelihoods depend on trust and audience relationships.

What happened?

According to Substack, unauthorized access allowed attackers to view certain user records containing email addresses and phone numbers. The company did not specify the exact number of users affected, but acknowledged that the breach stemmed from a third-party system vulnerability rather than its core publishing infrastructure.

Substack says it has since secured the affected systems, notified impacted users, and reported the incident to relevant regulators.

Why phone numbers matter more than passwords

While passwords can be changed, phone numbers and email addresses are permanent identifiers. Cybersecurity experts warn that such data can be exploited for phishing, SIM-swap attacks, targeted harassment, and identity correlation across platforms.

For independent journalists, activists, and niche creators—many of whom use Substack precisely to avoid platform dependency—this exposure raises serious safety and reputational risks.

Creator economy under pressure

Substack has positioned itself as a creator-first alternative to social media, emphasizing independence, ownership, and direct audience relationships. That positioning makes security incidents particularly damaging.

Unlike mass-market platforms, Substack hosts sensitive newsletters covering politics, finance, healthcare, and personal narratives. In some regions, disclosure of contact details could carry real-world consequences.

Substack’s response

https://substackcdn.com/image/fetch/%24s_%21rk0j%21%2Cf_auto%2Cq_auto%3Agood%2Cfl_progressive%3Asteep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ba3019e-295e-4833-aee8-750d0556c3ea_1418x816.gif

The company stated it is enhancing internal monitoring, auditing third-party integrations, and accelerating its security roadmap. Substack also reiterated that it does not sell user data and that the breach did not involve content access.

However, the lack of precise numbers and limited technical detail has drawn criticism from privacy advocates calling for greater transparency.

A broader industry problem

The incident reflects a wider challenge across SaaS and creator platforms: rapid growth often outpaces security maturity. As newsletter platforms expand monetization features—payments, analytics, SMS alerts—the volume of sensitive data they handle increases dramatically.

Regulators in the US and EU are increasingly scrutinizing how platforms disclose breaches and manage user consent.

What users should do now

Security professionals advise affected users to:

  • Be cautious of unsolicited emails or messages
  • Enable two-factor authentication where available
  • Monitor for phishing attempts referencing Substack activity
  • Avoid reusing email-linked credentials elsewhere

The trust test ahead

For Substack, the breach represents a critical trust test. The platform’s success depends not just on tools, but on creators’ confidence that their independence does not come at the cost of security.

As the creator economy professionalizes, privacy expectations will only rise.

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Website Upgradation is going on for any glitch kindly connect at office@startupnews.fyi

Editorial Team
StartupNews.fyi is a leading global startup and technology media platform known for its end-to-end coverage of the startup ecosystem across India and key international markets. Launched with the vision of becoming a single gateway for founders, investors, and ecosystem enablers, StartupNews.fyi has grown steadily over the years by publishing tens of thousands of verified news stories, insights, and ecosystem updates, reaching millions of startup enthusiasts every month through its digital platforms and communities.

More like this

Multiliquid, Metalayer Roll Out Instant Redemptions for Tokenized RWAs

Multiliquid and Metalayer Ventures have launched an institutional...

MFins Services Records Strong Growth in Solar and EV...

Mumbai (Maharashtra) , February 05: MFins Services Pvt....

How the School of Sciences at JAIN (Deemed-to-be University)...

Bengaluru (Karnataka) , January 30: In an era...

Popular

iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista melhor iptv portugal lista best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv best iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv portugal iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv iptv