Particle.news

Download on the App Store

Discord Puts ID Exposure at 70,000 in Third-Party Support Breach, Rejects Ransom Claims

The company attributes the breach to a compromised vendor account, pledging not to pay extortion.

Overview

  • Discord says its core systems were not breached, with attackers accessing a third‑party customer support environment used to handle tickets.
  • Threat actors claim they stole 1.6TB of data spanning about 8.4 million tickets affecting 5.5 million users and far more ID images, figures Discord disputes.
  • Potentially exposed data includes names, usernames, emails, IP addresses, support messages and attachments, and limited billing fragments, not passwords, full card numbers, or regular chat content.
  • Discord revoked the vendor’s access, notified impacted users from [email protected], and engaged external forensics, law enforcement, and data‑protection authorities.
  • Zendesk says its platform was not compromised, while the attackers say they used a compromised outsourced support agent account for 58 hours and sought $5 million in ransom later reduced to $3.5 million.