← Discord

2025 Discord — 5CA third-party customer service breach; ~70k government IDs

2025 70.0K records affected Share on X

Data compromised

Names, Discord usernames, emails, contact details, IP addresses, limited billing info (card last four, payment type, purchase history), customer-support messages, ~70,000 government-ID images from age appeals; not passwords or full card numbers

Technical writeup

Verified Discord disclosure — October 2025. Discord said an unauthorized party compromised third-party customer service provider 5CA (not a breach of Discord core systems) and accessed information from users who had contacted Customer Support and/or Trust & Safety, in an extortion attempt. Discord revoked the provider's ticketing access, engaged forensics and law enforcement, and emailed impacted users from [email protected]. Exposed data could include names, Discord usernames, emails, contact details, limited billing data (payment type, card last four, purchase history), IP addresses, support-ticket messages, limited internal training materials, and a small number of government-ID images — approximately 70,000 users may have had ID photos exposed from age-related appeals. Passwords, full card numbers, and general Discord messages/activity were not involved per Discord. 5CA disputed direct responsibility, citing a single employee's actions outside its systems.

Root cause

Unauthorized party compromised third-party customer service provider 5CA, gaining access to Discord ticketing data for users who contacted Customer Support or Trust & Safety (extortion attempt)

References