Substack has been hacked since October 2025.
They found out February 3rd. Didn't tell anyone publicly.
~700,000 accounts. Names, emails, phone numbers, social accounts, login metadata — all out there on cybercrime forums right now.
The irony of posting this on Substack is not lost on me.
Full breakdown + what to do: https://open.substack.com/pub/kaifisahil/p/substack-just-got-hacked?r=6p8e80&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
