Skip to main content
Breach Signal

Breach report

Messaging

Discord

Discord data breach affects at least 70,000 users

Hackers breached a third-party customer support system used by Discord and stole government ID photos of about 70,000 users submitted for age checks, then tried to extort the company for millions.

Reported by TechCrunch

Records exposed

70K

About 70,000 government ID images (attackers claimed data on 5.5 million users)

Scale vs. largest on file

When
2025
How they got in
Compromised third-party customer support vendor account
Sector
Messaging

In early October 2025, Discord disclosed that an unauthorized party had gained access to a third-party customer service system it used to handle support requests. The company initially said the intruders obtained information on users who had contacted its customer support or Trust and Safety teams. On October 9, Discord confirmed that about 70,000 users worldwide had government ID photos exposed.

The IDs were submitted by users appealing age-related decisions, a process that has grown as governments impose age verification rules. The UK's Online Safety Act, whose child-safety duties took effect in July 2025, pushed platforms including Discord to confirm users' ages, and users flagged as underage could submit ID photos or selfies to contest the decision. Beyond ID images, the exposed data included usernames, email addresses, IP addresses, messages exchanged with support agents, and for some users limited billing details such as the last four digits of a payment card.

According to reporting by BleepingComputer, the attackers gained access through a compromised account belonging to a support agent at a business process outsourcing provider, which gave them entry to Discord's Zendesk support instance for about 58 hours starting September 20. The hackers claimed to have stolen far more than Discord acknowledged, saying they held data on 5.5 million users and around 1.5 terabytes of files, and demanded a ransom that reportedly started at $5 million before dropping to $3.5 million. Discord called those claims inaccurate, said it would not pay, and described the figures as part of an extortion attempt.

Discord said it cut off the vendor's access, notified affected users and relevant data protection authorities, and worked with law enforcement. It did not publicly name the vendor, and a support company that was identified in media reports denied being responsible. The incident drew heavy criticism from privacy advocates, who argued that it illustrated the dangers of requiring users to hand over identity documents to online services.

The breach is a prime example of third-party risk: Discord's own systems were not directly compromised, but a vendor with privileged access became the weak point. It highlights the importance of strict access controls and monitoring for outsourced support staff, and of deleting sensitive verification data promptly. As age checks spread, the case is likely to shape debates over how, and whether, platforms should store ID images at all.

More from the wire

More in Messaging.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.