⚡ TL;DR
- Hackers accessed Substack's systems in October 2025. Substack did not catch it until February 3, 2026. That is four months of your data sitting in someone else's hands.
- Nearly 700,000 user records were leaked, including email addresses, phone numbers, names, bios, social media handles, and Stripe IDs.
- Passwords and full financial data were not part of the breach, but what was leaked is more than enough to cause serious damage through credential stuffing and targeted phishing.
- This is a 5-step, 20-minute response plan you can do right now. Not tomorrow. Right now.
- The pattern is the same after every breach: companies take months to detect it, your data gets leaked, you get a vague email, and then you are on your own. You cannot outsource your security.
The Substack breach 2026 exposed nearly 700,000 user records, and if you woke up to an email from CEO Chris Best apologizing for it, you are probably wondering what this actually means for you and what you should do about it.
I have spent over a decade working in cybersecurity and DevSecOps, and I have seen this pattern play out hundreds of times. A company gets breached, they send a vague email, users panic for a day, and then nothing changes. Most people do not know what steps to actually take, so they take none.
That ends here. I am going to walk you through exactly what is at risk and what to do about it in the next 20 minutes. Not tomorrow. Not "when you get around to it." Right now, while you are thinking about it.
The 60-Second Version of What Happened
Hackers accessed Substack's systems back in October 2025. Substack did not catch it until February 3, 2026. That is four months of your data sitting in someone else's hands without anyone telling you.
Nearly 700,000 user records were leaked on a hacking forum, including:
| What Was Leaked | Risk Level | What Attackers Can Do With It |
|---|---|---|
| Email address | Critical | Password resets, phishing targets, credential stuffing |
| Phone number | Critical | SMS phishing (smishing), SIM swap attacks, 2FA bypass |
| Name + Bio | High | Personalized social engineering, spear phishing |
| Social media handles | High | Cross-platform targeting, identity research |
| Stripe IDs | Medium | Impersonate billing support, payment-related scams |
| Internal metadata | Medium | Platform-specific targeted attacks |
Passwords and full financial data were not part of the breach. But as you will see below, what was leaked is more than enough to cause serious damage.
Why "Just an Email and Phone Number" Is a Bigger Deal Than You Think
I hear this after every breach. "They only got my email. Who cares?"
Here is who cares: the people who are about to use that information against you.
Your email address and phone number are the keys to almost every account you own. Think about it. When you reset a password, where does the link go? Your email. When you verify your identity with two-factor authentication, where does the code go? Your phone. Attackers now have both.
According to Verizon's 2025 Data Breach Investigations Report, 86% of breaches involve stolen credentials. Credential stuffing attacks, where hackers take leaked emails from one breach and try those same email/password combinations on hundreds of other sites, succeed against roughly 0.1-2% of accounts. That sounds small until you realize attackers run millions of attempts per day.
Combined with your name, bio, and social media handles from the Substack leak, they have everything they need to craft phishing emails and text messages that look completely legitimate. Not the obvious "Dear Customer" spam. Messages that reference your actual interests, your actual name, and the fact that you actually use Substack.
The inclusion of Stripe IDs in this breach is particularly concerning. While this is not your full payment information, sophisticated scammers can use Stripe IDs to impersonate billing support, sending emails like "There's an issue with your Substack subscription payment" that reference real transaction identifiers. These are extremely convincing because they contain data only Substack should have.
This is how accounts get compromised in 2026. Not through brute force password cracking. Through carefully targeted social engineering built on breach data exactly like this.
Your 20-Minute Breach Response Plan
I built this plan to work for any breach, not just Substack. Bookmark this page because you will need it again. Every one of these steps is something you can do right now without any technical background.
Step 1: Find Out How Exposed You Already Are (2 Minutes)
Before you can fix the problem, you need to know how big it is. Go to Have I Been Pwned and enter your email address.
This free tool, created by security researcher Troy Hunt, checks your email against every known data breach. If Substack is the only one that shows up, you are in decent shape. If you see five, ten, or twenty breaches listed, your email and personal details have been circulating for a while and this needs to become a priority.
Write down what you find. You will need it for the next steps.
You can also run your current passwords through our password strength checker to see if they are strong enough to resist modern cracking attempts.
Step 2: Lock Down Your Substack Account (3 Minutes)
Go directly to substack.com (type it into your browser, do not click any link from an email) and change your password.
Here is what matters: this new password needs to be completely unique. Not a variation of something you use elsewhere. Not your old password with a "2" at the end.
Generate a strong password that is at least 16 characters long with a mix of uppercase, lowercase, numbers, and symbols. You can use our secure password generator to create one in seconds. The best password is one you could never guess yourself.
Why 16 characters? We break down the math in our guide on why password length beats complexity, but the short version is: a 16-character random password would take centuries to crack with current technology. An 8-character password takes minutes.
Store it in a password manager. If you do not have one yet, that is okay. Step 4 covers that.
Step 3: Enable Two-Factor Authentication Everywhere That Matters (5 Minutes)
Two-factor authentication is the single most important thing you can do to protect your accounts. Even if an attacker gets your password, they cannot get in without the second factor.
Start with these accounts in this order. I am ranking them by how much damage a compromise would cause:
Priority 1: Your email. If someone gets into your email, they can reset passwords on everything else. This is your most important account. Enable 2FA on it first.
Priority 2: Your bank and financial accounts. For obvious reasons.
Priority 3: Social media and platforms like Substack. Especially anything connected to your real name and professional identity.
Use an authenticator app (Google Authenticator, Authy, or Microsoft Authenticator) rather than SMS codes when you have the option. SMS codes are better than nothing, but they can be intercepted through SIM swapping attacks, which is a real concern when attackers already have your phone number from this breach.
Need help setting this up? Our complete 2FA setup guide walks you through enabling two-factor authentication on every major platform step by step.
Step 4: Stop Reusing Passwords (5 Minutes to Start)
I am going to be direct with you. If you are reusing passwords across accounts, this breach just put all of those accounts at risk. Attackers take leaked emails from one breach and try those same email/password combinations on hundreds of other sites. It is automated, it is fast, and it works more often than you would think.
The fix is a password manager. It generates and stores unique passwords for every account, and you only need to remember one master password.
Here is how to get started today:
- Pick a password manager (see our recommendations below)
- Use our secure password generator to create a strong master password you can actually remember. Try a passphrase: four or five random words strung together with numbers and symbols mixed in. Our passphrase generator can help.
- Start adding your most important accounts. You do not need to do all of them today. Do your email, your bank, and your most-used accounts first. Add the rest over the next week.
Password Managers We Recommend
These are the password managers I trust and recommend to friends and family. All of them use zero-knowledge encryption, meaning even the company cannot see your passwords.
| Manager | Best For | Price | Key Feature |
|---|---|---|---|
Affiliate link. SPG earns a commission at no extra cost to you. NordPass |
Most users | $1.99/mo | Built-in breach scanner, from the makers of NordVPN |
| Proton Pass | Privacy-focused users | Free tier available | Swiss privacy laws, open source, full Proton ecosystem |
| RoboForm | Long-term value | $24/year | 25+ years in business, excellent autofill |
| Bitwarden | Budget-conscious | Free forever | Open source, self-host option |
Affiliate disclosure: I may earn a commission if you sign up through these links, at no extra cost to you. I only recommend tools I personally use or have thoroughly tested.
Affiliate link. I may earn a commission at no extra cost to you.