🧔♂️ A friendly human may check it before it goes live. More news here
Substack confirms data breach exposing user emails, phone numbers
Substack has confirmed a data breach affecting user email addresses and phone numbers, according to an email sent to users.
The company said an unauthorized third party accessed its systems in October, but sensitive information such as credit card details and passwords was not compromised.
Substack identified the breach in February and has since addressed the issue while launching an investigation.
The company did not specify the number of affected users or clarify why it took five months to detect the breach. It also did not say whether hackers demanded ransom or if there is evidence of data misuse.
Substack reported having over 50 million active subscriptions, including 5 million paid, as of March 2025.
The company did not provide details on potential misuse but advised users to be cautious with emails and texts.
No further information about the breach has been disclosed.
🔗 Source: TechCrunch
🧠 Food for thought
Implications, context, and why it matters.
The breach threatens Substack’s shift from cash-burning startup to sustainable platform
- This security failure lands at a tense moment for Substack. The company has raised over $200 million and is trying to prove its high-growth, low-debt business model can hold up 1.
- Earlier growth leaned on heavy spending to recruit top writers. That approach led to an operating loss of $4.3 million and negative total revenue in 2021 because of how writer deals were booked, including minimum guarantees treated as contra-revenue “partnership expenses” 2.
- The incident risks eroding the trust that supports its “subscription social network.” That model depends on close community ties and recurring payments that help back its valuation 3.
A data breach can pull regulators into the story
- In the U.S., an incident often sets enforcement in motion. It turns theoretical security gaps into real legal exposure 4.
- The FTC’s $575 million fine against Equifax targeted its security failures. The 2017 breach pushed those problems into the open 4.
- Regulatory risk also reaches disclosure. The SEC has sued firms like SolarWinds for allegedly misleading investors about cybersecurity weaknesses that surfaced after a breach 4.
- That pattern could bring scrutiny to what Substack previously told investors about cybersecurity controls and risks. A technical breakdown can then become a legal and financial threat.
Recent Substack developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




