惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
腾讯CDC
G
Google Developers Blog
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
有赞技术团队
有赞技术团队
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
M
MIT News - Artificial intelligence
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
美团技术团队
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Substack Confirms Data Breach, "Limited User Data" Compro...
2026-02-06 · via www.infosecurity-magazine.com

Newsletter platform Substack has confirmed it suffered a security incident, leading to the compromise of users’ email addresses and phone numbers.

Chris Best, the CEO of Substack, notified users of the data breach in an email sent to some users on February 5.

The CEO said his security team detected the incident on February 3, noticing “evidence of a problem with our systems that allowed an unauthorized third party to access limited user data without permission, including email addresses, phone numbers and other internal metadata.”

He also added that no financial information, including credit card numbers, or passwords were accessed.

Best further explained that the data collection occurred in October 2025 and claimed that the Substack security team has now “fixed the problem with our system that allowed this to happen.” No further information on the incident was provided.

Substack is now conducting a full investigation and is taking steps to improve our systems and processes to prevent this type of issue from happening in the future.

Speaking to Infosecurity, a Substack spokesperson said an unauthorized party was able to access limited account information "during a short window."

"Once we became aware, the issue was addressed and additional safeguards were put in place. We cannot share specifics about our security systems and processes, but we can confirm that the issue has been resolved," they added.

No further information on the incident was provided and the Substack CEO did not specify the number of affected users or clarify why the breach was only detected four months after it happened.

Substack reported having over 50 million active subscriptions, including five million paid, as of March 2025.

Javvad Malik, a lead security awareness advocate at KnowBe4 said that while transparent breach notifications “should always be commended,” this one is “a bit light on the details which does not help people accurately judge the risk and take concrete action.”

“The phrase 'limited user data' is particularly vague. Email addresses and phone numbers are enough for targeted phishing, SIM-swap attempts, or doxxing. Even if passwords weren’t accessed, attackers don’t need passwords if they can socially engineer users,” Malik said.

“The timeline is significant. If the data was accessed in October 2025, but only just disclosed, it's a significant dwell time. That isn't to say there's negligence on part of Substack because detection can be difficult,” Malik commented. “But impacted users deserve a clearer explanation of how the breach was identified and which monitoring controls failed to detect it initially, and most importantly, what's changing as a result.”

Chris Hauk, a consumer privacy advocate at Pixel Privacy, urged Substack users to “practice extra care” when dealing with unexpected messages, emails or calls, while Paul Bischoff, also a consumer privacy advocate at Comparitech emphasized that they should be “on the lookout for targeted phishing emails and scams.”

Image credits: Azulblue / Shutterstock