2025 Discord — 5CA third-party customer service breach; ~70k government IDs
Data compromised
Names, Discord usernames, emails, contact details, IP addresses, limited billing info (card last four, payment type, purchase history), customer-support messages, ~70,000 government-ID images from age appeals; not passwords or full card numbers
Technical writeup
Verified Discord disclosure — October 2025. Discord said an unauthorized party compromised third-party customer service provider 5CA (not a breach of Discord core systems) and accessed information from users who had contacted Customer Support and/or Trust & Safety, in an extortion attempt. Discord revoked the provider's ticketing access, engaged forensics and law enforcement, and emailed impacted users from [email protected]. Exposed data could include names, Discord usernames, emails, contact details, limited billing data (payment type, card last four, purchase history), IP addresses, support-ticket messages, limited internal training materials, and a small number of government-ID images — approximately 70,000 users may have had ID photos exposed from age-related appeals. Passwords, full card numbers, and general Discord messages/activity were not involved per Discord. 5CA disputed direct responsibility, citing a single employee's actions outside its systems.
Root cause
Unauthorized party compromised third-party customer service provider 5CA, gaining access to Discord ticketing data for users who contacted Customer Support or Trust & Safety (extortion attempt)
References
- https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service
- https://techcrunch.com/2025/10/09/discord-suffers-data-breach-impacting-at-least-70000-users/
- https://www.infosecurity-magazine.com/news/discord-data-breach-third-party/
- https://www.securityweek.com/customer-service-firm-5ca-denies-responsibility-for-discord-data-breach/
- https://5ca.com/blog/holding-statement-security-incident/