A data leak to a third-party customer service provider has exposed the personal data of some Discord users.

The incident did not affect Discord's core systems , and unauthorized access was limited to data managed by the company's support teams.
Discord recently discovered that an unauthorized party gained access to its management system customer support requestby breaching one of its third-party service providers. The company clarified that this was not a direct breach of its own servers.
See also: BYOD: Employee personal devices pose a risk to companies
The attacker's goal was to financially extort the company. Once the incident was detected, Discord immediately revoked the compromised provider's access to its systems to prevent further unauthorized activity.
The company has launched an internal investigation, has partnered with a leading cybersecurity firm for assistance, and is cooperating with law enforcement. The data exposed in the leak concerns users who interacted with Discord's Customer Support or Trust and Safety teams.

Discord: Data leak
The compromised information may include full names, Discord usernames, email addresses , and other contact details provided during support interactions. Limited billing information, such as payment type, purchase history, and the last four digits of a credit card number, may also have been compromised.
See also: Scattered Lapsus$ Hunters: Salesforce data leak site – 39 companies victims
Additionally, the leak included users' IP addresses and the content of messages exchanged with customer service agents. A small number of users who had submitted government identification documents, such as driver's licenses or passports for age verification purposes, were also affected.
Discord has assured users that full credit card numbers, CCV codes, private platform messages, and account passwords were not involved in this incident. In response to the attack, Discord has notified relevant data protection authorities and is actively reviewing the security controls of its third-party providers.
The company is in the process of contacting all affected users directly via email. These official notifications will be sent from [noreply@discord.com]. Discord has warned users that it will not contact them by phone regarding this matter and advised them to be wary of potential phishing attempts.
See also: Cybercriminals imitate well-known brands to scam users

Affected users are encouraged to remain vigilant and carefully review any suspicious messages or communications they receive. Discord has emphasized its commitment to user privacy and is taking further steps to review third-party systems to ensure they meet the company's security standards and to prevent similar incidents in the future.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
