Discord, the popular voice, video, and text communication platform, has disclosed a security incident stemming from the compromise of one of its third-party customer service providers. The breach, which was part of an apparent extortion attempt, did not affect Discord’s core systems directly, but exposed sensitive data from a limited number of users who had previously contacted the company’s Customer Support or Trust & Safety teams.

This incident highlights the pervasive security risk posed by external vendors who handle sensitive customer information, even when a company’s internal infrastructure remains secure.
The Scope of the Compromise
The unauthorized party gained access to the third-party provider’s support ticketing system, resulting in the exposure of several categories of user data. Discord has emphasized that the data stolen was confined to interactions with customer support agents.
The compromised information may include:
- Identity and Contact Details: Name, Discord username, email address, and other contact details provided to customer support.
- Network Information: User IP addresses.
- Support Records: The full contents of messages exchanged with customer service agents.
- Financial Data (Limited): Limited billing information, such as the payment type, the last four digits of credit card numbers, and purchase history associated with the account.
- Highly Sensitive Documents: A small number of government-issued photo IDs (e.g., driver’s licenses and passports) from users who had submitted the documents to appeal age determination decisions.
Discord has confirmed that critical security elements remain untouched. Full credit card numbers, CCV codes, user passwords, and authentication data were not impacted by the breach. Furthermore, no messages or activity outside of the compromised customer support conversations were accessed.
Response and Practical Advice for Users
Upon discovery, Discord took immediate and decisive technical action: it instantly revoked the third-party provider’s access to its ticketing system to stop any further unauthorized activity. The company has launched an internal investigation, engaged a computer forensics firm, and is cooperating with law enforcement. Discord has also notified relevant data protection authorities.
Discord has begun notifying all affected users directly via email, specifically indicating if their government-issued ID documents may have been accessed.
While passwords are secure, the exposure of email addresses, IP addresses, and personal details creates a heightened risk of phishing and social engineering attacks. Users are strongly advised to remain vigilant regarding any unsolicited communication, especially those purporting to be from Discord, as scammers might use the stolen details to personalize messages and make them appear more convincing. Discord emphasizes that its staff will never contact users by phone or request personal information or payment for support-related matters. Users should report suspicious activity immediately.