Substack says intruder lifted emails, phone numbers in months-old breach
ID: 7798b51a-2ad5-5e75-8fa1-ae3908ab4853
STIX ID: report--7798b51a-2ad5-5e75-8fa1-ae3908ab4853
Feed Name: The Register (Security)
Substack disclosed that an unauthorized third party accessed and shared user contact information (email addresses, phone numbers, and internal account metadata) in October 2025, with the compromise only detected in February 2026. The company says passwords and financial data were not affected, has patched the vulnerability and opened an investigation, but a threat actor later advertised a dataset of nearly 700,000 alleged records on a cybercrime forum; users are being warned to watch for phishing and other misuse while the scope and linkage of the public dataset to the breach remain unclear.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
