Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Substack

Substack Vendor Cyber Rating & Cyber Score

substack.com

Substack is a new media app that connects you with the creators, ideas, and communities you care about most. Founded in 2017, Substack is building a new economic engine for culture by putting publishers in charge and enabling subscribers to support the work they deeply value. There are more than 5 million paid subscriptions to writers and creators across the Substack network.


Substack A.I CyberSecurity Scoring

Substack
Company Information
Website:http://substack.com
Employees number:2,843
Number of followers:72,365
NAICS:519131
Industry Type:Online Audio and Video Media
Homepage:substack.com
Substack Risk Score (AI oriented)
Between 0 and 549
logo
SubstackOnline Audio and Video Media
Updated:
27/07/2026
522/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Substack Global Score (TPRM)
xxxx
logo
SubstackOnline Audio and Video Media
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Substack
SubstackCritical
Current Score
522C (CRITICAL)
01000
3 incidents
-91 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
525Before Incident
JULY 2026
520Before Incident
JUNE 2026
515Before Incident
MAY 2026
511Before Incident
APRIL 2026
508Before Incident
MARCH 2026
662Before Incident
Breach
01 Mar 2026Substack
Betterment, Substack, ADT, Amtrak, Hallmark, CarGurus, Panera Bread and McGraw Hill: Sextortion scammers are exploiting ShinyHunters data leaks

Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme

498After Incident
CRITICAL-164
MCGSUBAMTADTHALPANCARBET1785169886
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme Cybercriminals are leveraging email addresses from past ShinyHunters data breaches to lend false credibility to a new wave of sextortion scams, demanding $2,000 in Bitcoin from victims. The campaign, reported by BleepingComputer, targets individuals whose personal data was exposed in breaches of companies like Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill, as well as those affected by the Canvas data breach at a California community college. The scam emails falsely claim to be from ShinyHunters, alleging that the group has compromised victims’ devices, recorded explicit content via webcams, and threatens to leak the footage unless payment is made within 48 hours. A sample email includes a Bitcoin wallet address currently showing no transaction activity and falsely asserts access to browsing history, contacts, and other sensitive data. Despite the threats, no evidence supports the claims. ShinyHunters has denied involvement, and security experts confirm the emails are bluffs, relying on psychological manipulation rather than actual malware or recordings. The scammers likely obtained the email lists from publicly leaked data after ShinyHunters’ failed extortion attempts. The $2,000 demand marks an increase from typical sextortion scams, possibly indicating the scammers acquired the data through purchase or direct download. While the emails vary in sophistication some appearing AI-polished they uniformly lack verifiable proof. Security researchers emphasize that responding to such emails can confirm an active account, leading to further targeting. Victims are advised to ignore the threats, avoid engaging with the scammers, and report the emails as spam. If the message includes a previously used password, users should change it immediately and enable two-factor authentication (2FA). The campaign underscores how leaked data continues to fuel cybercrime, even when the original breach has been addressed.
INCIDENT DETAILS -
TYPE
Sextortion Scam
MOTIVATION
Financial gain
IMPACT
Financial Loss: $2,000 Bitcoin demand per victimData Compromised: Email addresses, previously exposed personal data (no new breach confirmed)Brand Reputation Impact: Potential reputational harm to affected entities due to association with leaked dataIdentity Theft Risk: Increased risk due to exposure of personal data
DATA BREACH
Type Of Data Compromised: Email addresses, personal data (from previous breaches)Sensitivity Of Data: Low to medium (email addresses, no confirmed new breach)Data Exfiltration: No evidence of new data exfiltrationPersonally Identifiable Information: Email addresses, potential passwords (if reused)
FEBRUARY 2026
715Before Incident
Breach
03 Feb 2026Substack
Substack: Substack data breach exposed users’ emails and phone numbers

Substack 2025 Data Breach Exposing User Email Addresses and Phone Numbers

660After Incident
CRITICAL-55
SUB1770295740
Substack Discloses 2025 Data Breach Exposing User Email Addresses and Phone Numbers Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. In an email sent to affected account holders, CEO Chris Best confirmed that an unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure. The breach involved email addresses, phone numbers, and internal metadata, but Substack stated there is no evidence the data has been misused. The company has since patched the vulnerability and is conducting a full investigation while strengthening its security measures to prevent future incidents. No details were provided on the root cause of the breach or the total number of impacted users. Best apologized for the incident, acknowledging the company’s failure to adequately protect user data. Substack has not yet responded to requests for further clarification on the scope of the breach.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Email addresses, phone numbers, internal metadataBrand Reputation Impact: Acknowledged failure to protect user dataPayment Information Risk: None (credit card details and financial information remained secure)
DATA BREACH
Type Of Data Compromised: Email addresses, phone numbers, internal metadataSensitivity Of Data: Moderate (PII but no financial data)Personally Identifiable Information: Email addresses, phone numbers
JANUARY 2026
715Before Incident
DECEMBER 2025
714Before Incident
NOVEMBER 2025
713Before Incident
OCTOBER 2025
765Before Incident
Breach
10 Oct 2025Substack
Substack: Substack data breach exposes emails and phone numbers

Substack Data Breach Exposes User Email Addresses and Phone Numbers

711After Incident
CRITICAL-54
SUB1771967867
Substack Data Breach Exposes User Email Addresses and Phone Numbers Substack, the popular newsletter platform used by writers and creators, confirmed a data breach that exposed user email addresses, phone numbers, and internal metadata. The unauthorized access occurred in October 2023 but was not detected until February 3, 2024, leaving user data potentially exposed for months. According to Substack CEO Chris Best, the breach did not compromise passwords, credit card numbers, or financial information. The company stated it has since resolved the system issue and launched a full investigation, though it has not provided details on why the breach went undetected for so long or what specific safeguards are now in place. While Substack reported no evidence of misuse, exposed contact details such as email addresses and phone numbers can be leveraged in phishing attacks, where scammers craft personalized messages referencing subscriptions or account activity to trick users into clicking malicious links. The incident highlights ongoing security risks for even niche platforms, raising concerns about detection delays and transparency in breach responses. Substack has urged users to remain cautious of suspicious communications.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: User email addresses, phone numbers, internal metadataBrand Reputation Impact: Raised concerns about detection delays and transparency in breach responsesIdentity Theft Risk: Phishing attacks leveraging exposed contact details
DATA BREACH
Email addressesPhone numbersInternal metadataSensitivity Of Data: Moderate (contact details, no financial or password data)Email addressesPhone numbers
SEPTEMBER 2025
765Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Substack ?
?
What was Substack's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Substack's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Substack's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Substack's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Substack's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Substack's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Substack ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Substack's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?