4 ms·
Substack confirms data breach affects users’ email addresses and phone numbers
- witnessme 8mo agoI am still confused for days whether this is a real news or a hoax. Only a substack user saying they received this email. I did not. And there is no official statement by Substack. What is really going on here?
- parable 8mo agoI've seen the leaked data posted on forums. I'm assuming they're trying to minimize the bad PR from this incident by only doing what's legally required, which is to notify affected users. They're likely not obligated to notify the broader public. Whether they should be obligated to do so is another discussion entirely.
- meitham 8mo agoCould you please tell me which forum this was posted on
- parable 8mo agoI'm fairly sure even mentioning the name of the forum isn't allowed on HN. It should be trivial to find it yourself, though. I also replied to someone else with the CSV headers if you're only trying to find out what exactly was included in the leak: https://news.ycombinator.com/item?id=46932380 https://news.ycombinator.com/item?id=46932380 Also, keep in mind that this is a partial leak. The data was scraped from some leaky endpoint which was patched out before every user could be scraped. Only users who were in the partial leak received emails (I have two accounts, only one received an email). If you're a Substack user but didn't receive an email, I'd assume you're not in the leak. Troy Hunt should load it into HIBP eventually, and those concerned can check there if they don't want to seek the leak out on their own.
- chrisjj 8mo ago> this is a partial leak. Substack PR probably love this. Like a gas tank has a partial leak.
- parable 8mo agoThis is actually a great analogy for why companies should take small data leaks seriously. A leak is a leak. Also, to clarify, I don't mean to appear as though I'm discrediting this leak or downplaying its severity. I only mentioned that it was a partial leak to offer an explanation as to why some users received emails and others didn't, as witnessme's comment seemed confused about this.
- squigz 8mo ago> I'm fairly sure even mentioning the name of the forum isn't allowed on HN. I'm not sure this would be the case? I've seen plenty of links to content of questionable legality shared on HN.
- shawabawa3 8mo ago>I'm fairly sure even mentioning the name of the forum isn't allowed on HN Well let's find out I did a tiny bit of research, pretty sure it's BreachForums (https://en.wikipedia.org/wiki/BreachForums https://en.wikipedia.org/wiki/BreachForums)
- direwolf20 8mo agoBreachForums was shut down
- shawabawa3 8mo agoSeems like every time it gets shut down it starts right back up again This source claims it's Breach forums but no idea if it's reliable https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/ https://www.bleepingcomputer.com/news/security/newsletter-pl...
- proactivesvcs 8mo agoIt recently popped up on the HIBP feed; they tend to be pretty careful when checking the veracity of claims. https://haveibeenpwned.com/Breach/Substack https://haveibeenpwned.com/Breach/Substack
- ntoskrnl_exe 8mo agoAccording to Have I Been Pwned, 663 thousand accounts were in the breach. You can verify your address there.
- ochronus 8mo agoI don't think it's fake - it explains why suddenly I got a ton of "verify your registration to XYZ" emails in the past week.
- Mordisquitos 8mo agoDo you reside outside of the EU (and outside anywhere where GDPR equivalents are enforced)? Maybe that would explain it. Under GDPR, a business has the obligation to inform users if they have been affected by a data breach. That could hypothetically explain why Substack would inform some users (those protected by GDPRish legislation) while keeping it quiet towards the rest of them.
- GeorgeOldfield 8mo agoit's real, i have the leak.
- slopusila 8mo ago> including email addresses, phone numbers, and other unspecified “internal metadata.” > Substack specified that more sensitive data, such as credit card numbers, passwords, and other financial information, was unaffected. I hate it when companies do this. passwords and credit card numbers are easily changed. names, emails and phone numbers are not.
- parable 8mo agoThis is what I've been saying for years. I really could care less if my passwords were leaked. My phone number, on the other hand, is near-impossible to change. The fact that VoIP/virtual numbers are blacklisted from use almost everywhere doesn't help anything, because otherwise I would just use a ton of cheap rented numbers. The same goes for full names on file, physical addresses, and other hard-to-change information. Passwords have been the least of my concerns since password managers were invented. You could, in theory, use a custom domain or email aliasing service like SimpleLogin or Addy to combat the email address issue, though websites like GitHub have been known to block emails created with an aliasing service. I could go on about why that move does next to nothing to combat actual abuse; any spammer worth their salt can just buy a bunch of Gmail accounts or Outlook accounts instead.
- hikkerl 8mo ago>I really could care less if my passwords were leaked couldn't*
- UqWBcuFx6NV4r 8mo ago[flagged]
- jstanley 8mo agoIt is a common saying, but the saying is "couldn't care less"
- 8mo ago
- dickiedyce 8mo agoOoopsie... possibly a problem for some folks: https://www.theguardian.com/media/2026/feb/07/revealed-how-substack-makes-money-from-hosting-nazi-newsletters https://www.theguardian.com/media/2026/feb/07/revealed-how-s...
- _n66o 8mo ago[flagged]
- lostlogin 8mo ago> some folk A very specific folk. Volksgemeinschaft is a German expression meaning "people's community", "folk community", "national community", or "racial community", depending on the translation of its component term Volk. https://en.wikipedia.org/wiki/Volksgemeinschaft https://en.wikipedia.org/wiki/Volksgemeinschaft
- dxdm 8mo agoYour quote leaves out the most interesting part: the word is now associated with some particularly folksy folk who notoriously used it in their. genocidal ideology > The concept was notoriously embraced by the newly founded Nazi Party in the 1920s, and eventually became strongly associated with Nazism after Adolf Hitler's rise to power. (From your Wikipedia link.)
- lostlogin 8mo agoYeah - I thought people would make the connection from the bit I posted. ‘Folksy folk’ is a great euphemism.
- BiteCode_dev 8mo agoLooked up NatSocToday on Substack, and they do have the swastika as a banner; they don't even hide or be subtle about it. Full on nazi, in plain sight. And plot twist, they are anti-Trump. I'm overwhelmed.
- 8mo ago
- iamacyborg 8mo agoSo, is the breach for substack users or for people who subscribed to substack users’ newsletters?
- parable 8mo agoAs far as I know, it only contains users who have made Substack profiles. Regular subscribers don't seem to be included, though I could be wrong.
- genie3io 8mo ago[dead]
- ArchieScrivener 8mo agoIsrael hacked a US based company and leaked data because they couldn't directly censor them?
- rvz 8mo agoThe AI agents are throwing another party celebrating over yet another data breach where they can train on this data and can now get to know us even more for personalized conversations about our Substack activity.
- chrisjj 8mo agoThey'll also be training on the hack experience to make the next "AI" better at its job.
- metalman 8mo agocant we just take it as a given that since the entire internet is scraped every 4hr's an 10 min, and then ransacked by every AI big tech, nation state, and the over achiving geeks have at there disposal, and therefore there is nothing that isn't "breached", multiply, and updated?, upbreached! daily.