The hidden risk of long-term cyber intrusions
Earlier this year, Substack confirmed a significant security breach in which an unauthorised third party accessed user email addresses, phone numbers, and internal metadata after infiltrating systems back in October 2025. The breach went undetected for five months, highlighting critical gaps in monitoring, alerting, and incident response processes.
While no passwords, credit card numbers or financial data were exposed, the incident still poses risks.
Expert Insight
*“This breach highlights a problem many organisations face: attackers often spend months inside systems without detection. Email addresses and phone numbers may seem low‑risk, but when combined with internal metadata, they offer a powerful toolkit for targeted phishing, impersonation, or further intrusion.
The real lesson here is that prevention alone isn’t enough. Organisations must assume breaches will happen and focus on rapid detection, segmentation, and minimising further exposure supported by ongoing user education and a robust recovery plan”*
Carl Whitham, Head of Managed IT
How to prevent a breach like this
Here are practical measures every organisation should follow:
- Continuous monitoring & anomaly detection: Deploy real‑time monitoring tools, behavioural analytics, and alerting systems to flag unusual access patterns early.
- Zero‑trust & segmentation: Zero‑trust architecture and micro‑segmentation reduce what attackers can access, even if they get in.
- Regular penetration testing: Ongoing testing helps uncover vulnerabilities before attackers do, especially legacy systems or overlooked components that store internal metadata.
- Enhanced metadata protection: Organisations should classify and protect metadata the same way they protect personal data.
- Phishing awareness & user vigilance: Stay cautious of suspicious messages and equip teams with regular training and real‑world simulation campaigns.
Implementing these measures requires the right tools, expertise, and ongoing support, this is where partnering with a trusted security provider becomes critical.
Partnering with Bitdefender for next-level protection
We combine our hands‑on security expertise with Bitdefender’s industry‑leading threat prevention, detection and response technology.
This partnership enables us to deliver enterprise-grade security designed to detect and stop threats before they escalate.
What we deliver:
- Advanced endpoint protection
- 24/7 monitoring & rapid incident response
- Proactive vulnerability management
- Phishing & social engineering defence
- Scalable security solutions