Breach report
MessagingDiscord
Discord data breach affects at least 70,000 users
Hackers breached a third-party customer support system used by Discord and stole government ID photos of about 70,000 users submitted for age checks, then tried to extort the company for millions.
Reported by TechCrunch
Records exposed
70K
About 70,000 government ID images (attackers claimed data on 5.5 million users)
Scale vs. largest on file
- When
- 2025
- How they got in
- Compromised third-party customer support vendor account
- Sector
- Messaging
In early October 2025, Discord disclosed that an unauthorized party had gained access to a third-party customer service system it used to handle support requests. The company initially said the intruders obtained information on users who had contacted its customer support or Trust and Safety teams. On October 9, Discord confirmed that about 70,000 users worldwide had government ID photos exposed.
The IDs were submitted by users appealing age-related decisions, a process that has grown as governments impose age verification rules. The UK's Online Safety Act, whose child-safety duties took effect in July 2025, pushed platforms including Discord to confirm users' ages, and users flagged as underage could submit ID photos or selfies to contest the decision. Beyond ID images, the exposed data included usernames, email addresses, IP addresses, messages exchanged with support agents, and for some users limited billing details such as the last four digits of a payment card.
According to reporting by BleepingComputer, the attackers gained access through a compromised account belonging to a support agent at a business process outsourcing provider, which gave them entry to Discord's Zendesk support instance for about 58 hours starting September 20. The hackers claimed to have stolen far more than Discord acknowledged, saying they held data on 5.5 million users and around 1.5 terabytes of files, and demanded a ransom that reportedly started at $5 million before dropping to $3.5 million. Discord called those claims inaccurate, said it would not pay, and described the figures as part of an extortion attempt.
Discord said it cut off the vendor's access, notified affected users and relevant data protection authorities, and worked with law enforcement. It did not publicly name the vendor, and a support company that was identified in media reports denied being responsible. The incident drew heavy criticism from privacy advocates, who argued that it illustrated the dangers of requiring users to hand over identity documents to online services.
The breach is a prime example of third-party risk: Discord's own systems were not directly compromised, but a vendor with privileged access became the weak point. It highlights the importance of strict access controls and monitoring for outsourced support staff, and of deleting sensitive verification data promptly. As age checks spread, the case is likely to shape debates over how, and whether, platforms should store ID images at all.