为什么Substack没有关于数据泄露的官方声明?
Substack confirms data breach affects users’ email addresses and phone numbers

原始链接: https://techcrunch.com/2026/02/05/substack-confirms-data-breach-affecting-email-addresses-and-phone-numbers/

Substack 近期确认发生数据泄露,影响用户信息。2023年10月,未经授权的第三方获取了电子邮件地址、电话号码和部分内部元数据。重要的是,信用卡详细信息和密码等敏感数据仍然安全。 Substack 在2月份发现了此次泄露,并已修复漏洞,启动调查。CEO 克里斯·贝斯特为此次事件道歉,承认数据保护方面存在失误。 该公司尚未披露受影响的用户数量或泄露的确切方法,也没有解释五个月的检测延迟。虽然 Substack 表示没有证据表明数据被滥用,但他们建议用户警惕可疑通信。 Substack 拥有超过 5000 万活跃订阅用户,其中 500 万为付费用户,并最近获得了 1 亿美元的融资。

Substack可能存在数据泄露,由于该公司缺乏官方沟通而引发担忧。报告显示,电子邮件地址、电话号码和未指定的“内部元数据”可能已被泄露,但Substack声称财务和登录信息仍然安全。 用户对姓名和电话号码等永久性数据泄露的担忧大于容易重置的密码。一些人建议使用电子邮件别名等方法,但承认这些方法通常会被服务阻止。 由于报告源自一位声称收到通知的单一用户,并且Substack本身没有确认,导致对泄露真实性的不确定性,情况仍然不明朗。Substack缺乏透明度正在加剧沮丧和猜测。
相关文章

原文

Newsletter platform Substack has confirmed a data breach in an email to users. The company said that in October, an “unauthorized third party” accessed user data, including email addresses, phone numbers, and other unspecified “internal metadata.”

Substack specified that more sensitive data, such as credit card numbers, passwords, and other financial information, was unaffected.

In an email sent to users, Substack chief executive Chris Best said that the company identified the issue in February that allowed someone to access its systems. Best said that Substack has fixed the problem and started an investigation.

“I’m reaching out to let you know about a security incident that resulted in the email address and phone number from your Substack account being shared without your permission,” said Best in the email to users. “I’m incredibly sorry this happened. We take our responsibility to protect your data and your privacy seriously, and we came up short here.”

It’s not clear what exactly the issue was with its systems, and the scope of the data that was accessed. It’s also not yet known why the company took five months to detect the breach, or if it was contacted by hackers demanding a ransom. TechCrunch asked the company for more details, and we will update our story if we hear back.

Substack did not say how many users are affected. The company said that it doesn’t have any evidence that users’ data is being misused, but did not say what technical means, such as logs, it has to detect evidence of abuse. However, the company asked users to take caution with emails and texts without any particular indicators or direction.

On its website, Substack says that its site has more than 50 million active subscriptions, including 5 million paid subscriptions — a milestone it reached last March. In July 2025, the company raised $100 million in Series C funding led by BOND and The Chernin Group (TCG), with participation from a16z, Klutch Sports Group CEO Rich Paul, and Skims co-founder Jens Grede.

Techcrunch event

Boston, MA | June 23, 2026

联系我们 contact @ memedata.com