Substack A.I CyberSecurity Scoring
Substack
Company Information
Website:http://substack.com
Employees number:2,843
Number of followers:72,365
NAICS:519131
Industry Type:Online Audio and Video Media
Homepage:substack.com
Substack Risk Score (AI oriented)
Between 0 and 549
SubstackOnline Audio and Video Media
Updated:
27/07/2026
27/07/2026
522/1000
Critical
C
Substack Global Score (TPRM)
xxxx
SubstackOnline Audio and Video Media
Score locked

SubstackCritical
Current Score
522C (CRITICAL)
01000
3 incidents
-91 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
525
JULY 2026
520
JUNE 2026
515
MAY 2026
511
APRIL 2026
508
MARCH 2026
662
Breach
01 Mar 2026 • Substack
Betterment, Substack, ADT, Amtrak, Hallmark, CarGurus, Panera Bread and McGraw Hill: Sextortion scammers are exploiting ShinyHunters data leaks
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme
498
CRITICAL-164
MCGSUBAMTADTHALPANCARBET1785169886
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme
Cybercriminals are leveraging email addresses from past ShinyHunters data breaches to lend false credibility to a new wave of sextortion scams, demanding $2,000 in Bitcoin from victims. The campaign, reported by BleepingComputer, targets individuals whose personal data was exposed in breaches of companies like Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill, as well as those affected by the Canvas data breach at a California community college.
The scam emails falsely claim to be from ShinyHunters, alleging that the group has compromised victims’ devices, recorded explicit content via webcams, and threatens to leak the footage unless payment is made within 48 hours. A sample email includes a Bitcoin wallet address currently showing no transaction activity and falsely asserts access to browsing history, contacts, and other sensitive data.
Despite the threats, no evidence supports the claims. ShinyHunters has denied involvement, and security experts confirm the emails are bluffs, relying on psychological manipulation rather than actual malware or recordings. The scammers likely obtained the email lists from publicly leaked data after ShinyHunters’ failed extortion attempts.
The $2,000 demand marks an increase from typical sextortion scams, possibly indicating the scammers acquired the data through purchase or direct download. While the emails vary in sophistication some appearing AI-polished they uniformly lack verifiable proof. Security researchers emphasize that responding to such emails can confirm an active account, leading to further targeting.
Victims are advised to ignore the threats, avoid engaging with the scammers, and report the emails as spam. If the message includes a previously used password, users should change it immediately and enable two-factor authentication (2FA). The campaign underscores how leaked data continues to fuel cybercrime, even when the original breach has been addressed.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
715
Breach
03 Feb 2026 • Substack
Substack: Substack data breach exposed users’ emails and phone numbers
Substack 2025 Data Breach Exposing User Email Addresses and Phone Numbers
660
CRITICAL-55
SUB1770295740
Substack Discloses 2025 Data Breach Exposing User Email Addresses and Phone Numbers
Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. In an email sent to affected account holders, CEO Chris Best confirmed that an unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure.
The breach involved email addresses, phone numbers, and internal metadata, but Substack stated there is no evidence the data has been misused. The company has since patched the vulnerability and is conducting a full investigation while strengthening its security measures to prevent future incidents. No details were provided on the root cause of the breach or the total number of impacted users.
Best apologized for the incident, acknowledging the company’s failure to adequately protect user data. Substack has not yet responded to requests for further clarification on the scope of the breach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
715
DECEMBER 2025
714
NOVEMBER 2025
713
OCTOBER 2025
765
Breach
10 Oct 2025 • Substack
Substack: Substack data breach exposes emails and phone numbers
Substack Data Breach Exposes User Email Addresses and Phone Numbers
711
CRITICAL-54
SUB1771967867
Substack Data Breach Exposes User Email Addresses and Phone Numbers
Substack, the popular newsletter platform used by writers and creators, confirmed a data breach that exposed user email addresses, phone numbers, and internal metadata. The unauthorized access occurred in October 2023 but was not detected until February 3, 2024, leaving user data potentially exposed for months.
According to Substack CEO Chris Best, the breach did not compromise passwords, credit card numbers, or financial information. The company stated it has since resolved the system issue and launched a full investigation, though it has not provided details on why the breach went undetected for so long or what specific safeguards are now in place.
While Substack reported no evidence of misuse, exposed contact details such as email addresses and phone numbers can be leveraged in phishing attacks, where scammers craft personalized messages referencing subscriptions or account activity to trick users into clicking malicious links.
The incident highlights ongoing security risks for even niche platforms, raising concerns about detection delays and transparency in breach responses. Substack has urged users to remain cautious of suspicious communications.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
765
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Substack ??
What was Substack's A.I Rankiteo Cyber Score in July 2026 ??
What was Substack's A.I Rankiteo Cyber Score in June 2026 ??
What was Substack's A.I Rankiteo Cyber Score in May 2026 ??
What was Substack's A.I Rankiteo Cyber Score in April 2026 ??
What was Substack's A.I Rankiteo Cyber Score in March 2026 ??
What was Substack's A.I Rankiteo Cyber Score in February 2026 ??
What was Substack's A.I Rankiteo Cyber Score in January 2026 ??
What was Substack's A.I Rankiteo Cyber Score in December 2025 ??
What was Substack's A.I Rankiteo Cyber Score in November 2025 ??
What was Substack's A.I Rankiteo Cyber Score in October 2025 ??
What was Substack's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Substack's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Substack ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Substack's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?