Overview
- Discord says its core systems were not breached, with attackers accessing a third‑party customer support environment used to handle tickets.
- Threat actors claim they stole 1.6TB of data spanning about 8.4 million tickets affecting 5.5 million users and far more ID images, figures Discord disputes.
- Potentially exposed data includes names, usernames, emails, IP addresses, support messages and attachments, and limited billing fragments, not passwords, full card numbers, or regular chat content.
- Discord revoked the vendor’s access, notified impacted users from [email protected], and engaged external forensics, law enforcement, and data‑protection authorities.
- Zendesk says its platform was not compromised, while the attackers say they used a compromised outsourced support agent account for 58 hours and sought $5 million in ransom later reduced to $3.5 million.