Substack Confirms Data Breach, "Limited
Substack did not specify the number of users affected by the data breach
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
Substack did not specify the number of users affected by the data breach
290K client records exposed in LockBit ransomware attack
1,435,174 records exposed — Dates of birth, Device information, Email addresses, Employers and 5 more
210K student records exposed
120K client records from 47 offices worldwide exposed via compromised email gateway
280K pharmaceutical manufacturing records exposed
670K agricultural customer records stolen
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability — SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This co
React Native Community CLI OS Command Injection Vulnerability — React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the M
280K restructuring records stolen
180K streaming platform records exposed
780K advisor and client records exposed
560K medical records compromised
450K customer records exposed in targeted attack
780K employee and operations records compromised
890K insurance records stolen in targeted attack
890K customer records stolen
210K enterprise supply chain records exposed
340K reinsurance policyholder records from global operations exposed in targeted attack
1.2M customer payment records exposed in POS breach
3.2M credit card applicant records exposed via new cloud misconfiguration — second incident
3.2M customer records exposed via SaaS vendor breach affecting loyalty program data
81M citizen health records from Aadhaar-linked database exposed via API vulnerability
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability — SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow a