Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachbreach-disclosure-notificationmass-credential-exposureunderground-data-leak

Discord User Data Exposed via Third-Party Customer Support Breach

Updated 3mo agoFirst seen Oct 4, 202523 sources

Attackers gained unauthorized access to a third-party customer service system used by Discord, resulting in the exposure of sensitive user data. The breach, which occurred on September 20, 2025, did not compromise Discord’s core infrastructure but targeted a helpdesk provider that managed customer support and Trust and Safety interactions. The attackers obtained personally identifiable information, including real names, Discord usernames, email addresses, and IP addresses of users who had contacted Discord’s support teams. In addition to contact details, the breach exposed partial payment information, such as the last four digits of credit cards and payment types, as well as purchase history for some users. Notably, a subset of affected users had submitted government-issued identification documents, such as driver’s licenses and passports, for account appeals or age verification, and these scanned IDs were also accessed by the attackers. The attackers demanded a ransom from Discord, threatening to leak the stolen information if their demands were not met, indicating a financially motivated campaign. Discord responded by immediately revoking the support provider’s access to its ticketing system, launching an internal investigation, and engaging a leading computer forensics firm to assist with remediation. Law enforcement agencies were also notified and involved in the investigation. The company publicly disclosed the incident and notified affected users, emphasizing that full credit card numbers and account passwords were not compromised. The breach highlights the risks associated with storing sensitive data, such as government IDs, in third-party systems, especially as regulatory requirements push platforms to collect more personal information for age verification. Security experts note that customer support platforms often become attractive targets for cybercriminals due to the concentration of sensitive user data. The incident underscores the importance of minimizing data retention and ensuring that sensitive information is not stored longer than necessary in support systems. Discord’s experience mirrors previous breaches at other major platforms where helpdesk systems were exploited to access user data. The company’s swift response aimed to contain the breach and prevent further unauthorized access. The exposure of government-issued IDs is particularly concerning, as it increases the risk of identity theft for affected users. The breach serves as a cautionary tale for organizations relying on third-party vendors to handle sensitive customer interactions. Ongoing investigations are expected to provide further insights into the attackers’ methods and the full scope of the compromised data. Discord has committed to reviewing and strengthening its data handling and vendor management practices in the wake of the incident.

Share:
Discord User Data Exposed via Third-Party Customer Support Breach
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Oct 9, 20259mo ago

Discord rejects mass-breach claims and confirms limited exposure

Discord publicly refuted the attackers' claim of a 5.5 million-user breach and reiterated that the known exposure was limited to about 70,000 ID photos and related support data. This marked a key attribution and impact update in the incident narrative.

Discord says about 70,000 government IDs were exposed

Discord clarified that the incident's confirmed impact was far smaller than the attackers claimed, saying roughly 70,000 users may have had government ID images exposed. The affected users had submitted IDs during age-related appeal reviews handled by Customer Support or Trust & Safety.

Oct 8, 20259mo ago

Hackers claim Discord breach exposed 5.5 million users

Attackers publicly claimed the breach affected 5.5 million Discord users, dramatically inflating the apparent scale of the incident. This claim was reported by multiple outlets but was not accepted by Discord.

Oct 7, 20259mo ago

Discord warns affected users after third-party breach

Discord began warning impacted users about the breach and advised that official notifications would come by email. The company also emphasized it would not contact affected users by phone, reflecting concern about follow-on scams.

Oct 6, 20259mo ago

Coverage links the breach to a ransom or extortion attempt

Subsequent reporting indicated the vendor hack was part of a ransom or extortion bid by the attackers. This added a criminal motive to the incident beyond simple unauthorized access and data theft.

Oct 4, 20259mo ago

Reports detail exposed support chats, billing data, and IDs

Follow-on reporting said the stolen data included customer support tickets and personally identifiable information such as billing details and identity documents submitted during support interactions. The exposed records were tied to users who had contacted Customer Support or Trust & Safety.

Oct 3, 20259mo ago

Discord discloses third-party support data breach

Discord publicly disclosed the security incident involving its third-party customer service provider and said support ticket data had been accessed. The company said it had revoked the vendor's access to Discord's ticketing system and began responding to the incident.

Discord's customer service vendor is compromised

An unauthorized party breached one of Discord's third-party customer service providers, gaining access to support-related data tied to Discord users. The intrusion affected information held in the vendor's ticketing environment rather than Discord's core platform.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
9 linked
DiscordAmazonValve CorporationTwitchRobloxZendeskScattered Lapsus$ HuntersOktaKolide
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.