I am still confused for days whether this is a real news or a hoax. Only a substack user saying they received this email. I did not. And there is no official statement by Substack. What is really going on here?
I've seen the leaked data posted on forums. I'm assuming they're trying to minimize the bad PR from this incident by only doing what's legally required, which is to notify affected users. They're likely not obligated to notify the broader public. Whether they should be obligated to do so is another discussion entirely.
According to Have I Been Pwned, 663 thousand accounts were in the breach. You can verify your address there.
It recently popped up on the HIBP feed; they tend to be pretty careful when checking the veracity of claims.
https://haveibeenpwned.com/Breach/Substack