Discord User Data Exposed via Third-Party Customer Support Breach
Attackers gained unauthorized access to a third-party customer service system used by Discord, resulting in the exposure of sensitive user data. The breach, which occurred on September 20, 2025, did not compromise Discord’s core infrastructure but targeted a helpdesk provider that managed customer support and Trust and Safety interactions. The attackers obtained personally identifiable information, including real names, Discord usernames, email addresses, and IP addresses of users who had contacted Discord’s support teams. In addition to contact details, the breach exposed partial payment information, such as the last four digits of credit cards and payment types, as well as purchase history for some users. Notably, a subset of affected users had submitted government-issued identification documents, such as driver’s licenses and passports, for account appeals or age verification, and these scanned IDs were also accessed by the attackers. The attackers demanded a ransom from Discord, threatening to leak the stolen information if their demands were not met, indicating a financially motivated campaign. Discord responded by immediately revoking the support provider’s access to its ticketing system, launching an internal investigation, and engaging a leading computer forensics firm to assist with remediation. Law enforcement agencies were also notified and involved in the investigation. The company publicly disclosed the incident and notified affected users, emphasizing that full credit card numbers and account passwords were not compromised. The breach highlights the risks associated with storing sensitive data, such as government IDs, in third-party systems, especially as regulatory requirements push platforms to collect more personal information for age verification. Security experts note that customer support platforms often become attractive targets for cybercriminals due to the concentration of sensitive user data. The incident underscores the importance of minimizing data retention and ensuring that sensitive information is not stored longer than necessary in support systems. Discord’s experience mirrors previous breaches at other major platforms where helpdesk systems were exploited to access user data. The company’s swift response aimed to contain the breach and prevent further unauthorized access. The exposure of government-issued IDs is particularly concerning, as it increases the risk of identity theft for affected users. The breach serves as a cautionary tale for organizations relying on third-party vendors to handle sensitive customer interactions. Ongoing investigations are expected to provide further insights into the attackers’ methods and the full scope of the compromised data. Discord has committed to reviewing and strengthening its data handling and vendor management practices in the wake of the incident.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
8 events from the most recent confirmed update back to the earliest known activity.
Discord rejects mass-breach claims and confirms limited exposure
Discord publicly refuted the attackers' claim of a 5.5 million-user breach and reiterated that the known exposure was limited to about 70,000 ID photos and related support data. This marked a key attribution and impact update in the incident narrative.
Discord says about 70,000 government IDs were exposed
Discord clarified that the incident's confirmed impact was far smaller than the attackers claimed, saying roughly 70,000 users may have had government ID images exposed. The affected users had submitted IDs during age-related appeal reviews handled by Customer Support or Trust & Safety.
Hackers claim Discord breach exposed 5.5 million users
Attackers publicly claimed the breach affected 5.5 million Discord users, dramatically inflating the apparent scale of the incident. This claim was reported by multiple outlets but was not accepted by Discord.
Discord warns affected users after third-party breach
Discord began warning impacted users about the breach and advised that official notifications would come by email. The company also emphasized it would not contact affected users by phone, reflecting concern about follow-on scams.
Coverage links the breach to a ransom or extortion attempt
Subsequent reporting indicated the vendor hack was part of a ransom or extortion bid by the attackers. This added a criminal motive to the incident beyond simple unauthorized access and data theft.
Reports detail exposed support chats, billing data, and IDs
Follow-on reporting said the stolen data included customer support tickets and personally identifiable information such as billing details and identity documents submitted during support interactions. The exposed records were tied to users who had contacted Customer Support or Trust & Safety.
Discord discloses third-party support data breach
Discord publicly disclosed the security incident involving its third-party customer service provider and said support ticket data had been accessed. The company said it had revoked the vendor's access to Discord's ticketing system and began responding to the incident.
Discord's customer service vendor is compromised
An unauthorized party breached one of Discord's third-party customer service providers, gaining access to support-related data tied to Discord users. The intrusion affected information held in the vendor's ticketing environment rather than Discord's core platform.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
23 references tracked. Mallory keeps watching after this page renders.
Discord says hackers stole government IDs of 70,000 users
arstechnica.com
Open source70,000 government IDs were exposed in a Discord breach - could yours be next?
zdnet.com
Open sourceDiscord refutes claimed impact of third-party breach
scworld.com
Open sourceDiscord Says Hackers Stole 70,000 ID Photos, Dismisses Extortion Claims
hackread.com
Open sourceWhen Customer Support Becomes the Weakest Link: Lessons from the Discord Breach
zendata.security
Open sourceHackers steal identifiable Discord user data in third-party breach
bleepingcomputer.com
Open sourceDiscord discloses data breach after hackers steal support tickets
bleepingcomputer.com
Open sourceUpdate on a Security Incident Involving Third-Party Customer Service
discord.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


