A data breach at a third-party customer service provider has exposed the personal data of some Discord users, including names, email addresses, and a small number of scanned government-issued photo IDs.
The incident did not compromise Discord’s main systems, and the unauthorized access was limited to data handled by the company’s support teams.
Discord announced that it recently discovered an unauthorized party had gained access to its customer support ticketing system by compromising one of its third-party service vendors.
The company clarified that this was not a direct breach of Discord’s own servers. The attacker’s goal was reportedly to extort a financial ransom from the company. As soon as the incident was detected, Discord immediately revoked the compromised provider’s access to its systems to prevent further unauthorized activity.
The company has since launched an internal investigation, engaged a leading computer forensics firm to assist, and is collaborating with law enforcement agencies.
Discord Data Breach
The data exposed in the breach pertains to users who interacted with Discord’s Customer Support or Trust & Safety teams. The compromised information may include full names, Discord usernames, email addresses, and other contact details provided during support interactions.
Limited billing information, such as payment type, purchase history, and the last four digits of a credit card number, was also potentially accessed.
Furthermore, the breach included user IP addresses and the content of messages exchanged with customer service agents. Crucially, a small number of users who had submitted government-issued photo IDs like driver’s licenses or passports for age verification purposes had these sensitive documents exposed.
Discord has assured users that full credit card numbers, CCV codes, private platform messages, and account passwords were not involved in this incident.
In response to the attack, Discord has notified relevant data protection authorities and is actively reviewing the security controls of its third-party providers. The company is in the process of contacting all impacted users directly via email.
These official notifications will be sent from the address [email protected]. Discord has warned users that it will not contact them by phone regarding this matter and advised them to be cautious of potential phishing attempts.
Impacted users are encouraged to remain vigilant and scrutinize any suspicious messages or communications they receive.
Discord has emphasized its commitment to user privacy and is taking further steps to audit its third-party systems to ensure they meet the company’s security standards and prevent similar incidents in the future.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
Source: cybersecuritynews.com