11.1 C
Delhi
Saturday, January 17, 2026

Discord Vendor Breach Exposes User IDs in Ransom Attack

Discord Confirms Third-Party Vendor Breach Exposed User IDs in Ransom Plot

Discord has confirmed a significant data breach affecting thousands of users after hackers compromised its third-party customer support vendor. The incident exposed sensitive user information including government ID images and triggered ransom demands from the attackers.

Key Takeaways

  • 70,000 users had government ID photos exposed
  • Breach occurred via third-party vendor 5CA on September 20
  • Scattered Lapsus$ Hunters group claimed responsibility
  • Discord has terminated the vendor relationship

How the Discord Data Breach Unfolded

The security incident occurred on September 20, 2025, when attackers gained unauthorized access to 5CA, one of Discord’s third-party customer service providers. Importantly, this was not a direct breach of Discord’s own servers but rather a compromise of their external support vendor.

The exposed data includes Discord usernames, real names, email addresses, limited billing details, IP addresses, and messages exchanged with customer service agents. Most concerningly, approximately 70,000 users globally had government ID images exposed—documents that were submitted for age verification purposes.

About 70,000 users had ID images stolen in the latest third-party data breach
About 70,000 users had ID images stolen in the latest third-party data breach. (Tiffany Hagler-Geard/Bloomberg via Getty Images)

Ransom Demands and Threat Group Involvement

Reports indicate the attackers attempted to extort money from Discord using the stolen data. Bleeping Computer identified the Scattered Lapsus$ Hunters (SLH) threat group as claiming responsibility for the attack. This same group allegedly claims access to over a billion Salesforce records and is demanding ransom for those as well.

Discord’s Response and Security Measures

Discord disclosed the incident on October 3—13 days after the breach occurred. The company has taken several decisive actions:

  • Terminated the compromised vendor’s access
  • Launched an internal investigation with digital forensics experts
  • Notified all affected users globally
  • Alerted data-protection authorities and law enforcement
  • Initiated third-party vendor security audits

A Discord representative stated: “We want to address inaccurate claims by those responsible that are circulating online. First, as stated in our blog post, this was not a breach of Discord, but rather a third-party service we use to support our customer service efforts. Second, the numbers being shared are incorrect and part of an attempt to extort a payment from Discord. Of the accounts impacted globally, we have identified approximately 70,000 users that may have had government-ID photos exposed, which our vendor used to review age-related appeals. Third, we will not reward those responsible for their illegal actions. All affected users globally have been contacted, and we continue to work closely with law enforcement, data protection authorities and external security experts. We’ve secured the affected systems and ended work with the compromised vendor. We take our responsibility to protect your personal data seriously and understand the concern this may cause.”

Discord cuts ties with vendor 5CA and tightens its security investigations
Discord cuts ties with vendor 5CA and tightens its security investigations. (Kurt “CyberGuy” Knutsson)

6 Essential Security Steps for Affected Users

1. Enable Two-Factor Authentication

Activate 2FA on your Discord account using authenticator apps or SMS. This adds an extra verification layer that prevents unauthorized access even if your password is compromised.

2. Use Strong, Unique Passwords

Never reuse passwords across different platforms. Consider using a password manager to generate and store complex, unique passwords for each of your accounts.

3. Monitor for Suspicious Activity

Regularly check your Discord login history and email for unusual sign-in attempts. Consider identity protection services that scan the dark web for your credentials.

4. Be Wary of Phishing Attempts

Expect increased phishing emails following this breach. Verify all communications carefully—Discord will only contact you about this incident from noreply@discord.com.

5. Keep Software Updated

Ensure your operating system, apps, and antivirus software are current to protect against known vulnerabilities that attackers might exploit.

6. Consider Data Removal Services

Evaluate personal data removal services to reduce your digital footprint and make it harder for attackers to target you with personalized attacks.

The Bigger Picture: Third-Party Security Risks

This incident highlights the growing cybersecurity challenge of third-party vendor risks. As companies increasingly rely on external service providers, these vendors often become the weakest link in security chains. The Discord breach demonstrates how even robust internal security measures can be undermined by vulnerabilities in partner organizations.

The fundamental question remains: Should companies bear greater accountability for breaches originating from their third-party providers? This incident will likely fuel ongoing discussions about vendor security standards and corporate responsibility in the digital age.

Latest

iQOO Z11 Turbo Launched With 7,600mAh Battery & Snapdragon 8s Gen 3

iQOO Z11 Turbo debuts with a massive battery, 100W charging, and flagship Snapdragon 8s Gen 3 chip. Check price, specs, and launch details.

Microsoft Cuts Staff Library, 1,500 Azure Jobs in AI Push

Microsoft replaces employee library access with AI experiences and cuts 1,500 Azure jobs as part of a restructuring focused on cloud and artificial intelligence.

Grimes Sues Elon Musk’s xAI Over Grok Deepfakes, Says She Lives in Fear

Musician Grimes files lawsuit against Elon Musk's AI company, alleging its Grok chatbot created explicit deepfakes, sparking a major legal battle over AI abuse.

India’s Scramjet Success: Why Fighter Jets Still Use Conventional Engines

India joins the hypersonic club with scramjet tech. We explain why this breakthrough won't power fighter jets yet and what it means for missiles and space travel.

Elon Musk’s xAI Sued Over Grok AI Creating Explicit Deepfakes

Neuralink director Shivon Zilis files lawsuit alleging xAI's chatbot generated graphic deepfakes of her, highlighting the urgent AI safety crisis.

Topics

RIL Q3 Profit Rises 11% to ₹19,641 Crore, Beats Estimates

Reliance Industries posts strong Q3 results with profit up 10.9%, EBITDA growth of 16.7%, and robust performance across all business segments.

Budget 2026: Education Sector Demands Focus on Skills and Jobs

Industry and academia seek higher funding for skill development, NEP implementation, and tax incentives in the upcoming Union Budget to boost employability.

Mumbai Voter Turnout Hits 32-Year High in Lok Sabha Elections

Mumbai recorded 55.38% voter turnout in 2024 Lok Sabha polls, its second-highest in 32 years. Analysis reveals what drove the surge and what it means for the city's civic engagement.

Indian Scientists Uncover Cell’s Life-or-Death Decision Mechanism

Breakthrough research reveals how cells choose survival or self-destruction under stress, opening new paths to treat cancer, heart attacks, and Alzheimer's.

Spirit Release Date: Prabhas & Sandeep Reddy Vanga Film Set for Jan 2026

Sandeep Reddy Vanga announces January 10, 2026, as the release date for his pan-India film Spirit, starring Prabhas and Tripti Dimri.

BJP Breaks Sena Fortress, Wins Historic 2026 BMC Election

The BJP-led Mahayuti alliance ends the Thackeray dynasty's 30-year rule over Mumbai's civic body. Analysis on why Shiv Sena (UBT) crumbled and Congress stalled.

Wipro Declares Rs 6 Dividend as Q3 Profit Dips to Rs 3,119 Crore

Wipro announces Rs 6 per share interim dividend for FY25. Q3 net profit falls to Rs 3,119 crore, but order bookings surge 31% year-on-year.

Bhumi Pednekar’s Daldal Teaser Out, Series Premieres April 5 on Prime

Watch the gritty teaser for crime thriller 'Daldal' starring Bhumi Pednekar as a cop. The series premieres on Amazon Prime Video on April 5.
spot_img

Related Articles

Popular Categories

spot_imgspot_img