Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Badges, Bytes and Blackmail

February 7, 2026

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Discord Reveals Data Breach Following Third-Party Compromise
News

Discord Reveals Data Breach Following Third-Party Compromise

Team-CWDBy Team-CWDOctober 11, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Discord has revealed it has been targeted by a ransomware actor who has accessed customer data, including proof of age ID and billing information.

The incident was caused by the compromise of a third-party customer service provider, which has not been named.

“An unauthorized party targeted our third-party customer support services to access user data, with a view to extort a financial ransom from Discord,” the social platform wrote in a post on October 3.

The data breach impacts a limited number of customers who had contacted Discord through its customer support and/or trust and safety teams.

Information potentially compromised includes customer names, Discord account usernames, email and other contact details.

Limited billing details, such as payment type and the last four digits of credit cards were also impacted.

Other potentially affected data includes user IP addresses, messages exchanged with customer service agents and a small number of government ID images from users who had appealed an age determination.

Corporate data, such as training materials and internal presentations were accessed by the hackers.

The company is in the process of contacting impacted users via email from noreply@discord.com. It has told customers that no other communication channels will be used for this purpose, such as phone calls.

No figure has been given on the total number of users impacted by the breach. Discord has more than 200 million active users per month globally.

Discord said that full credit card numbers or CVV codes were not included in the data accessed. No password or authentication data was compromised.

Additionally, no messages or activity on Discord outside of communication with customer support were obtained by the attackers.

Law enforcement and relevant data protection authorities have been notified about the incident.

Another High-Profile Third-Party Attack

Discord said it took immediate action to mitigate the attack upon detection, including revoking the customer support provider’s access to its ticketing system.

The platform added that it has reviewed its security controls for third-party support providers.

Jake Moore, global cybersecurity advisor at ESET, commented: “This is a worrying breach, especially as it seems to have come through a trusted third-party rather than Discord itself. Third party weaknesses are often harder to monitor and control yet they still hold sensitive information and are becoming an increasingly common target for cybercriminals.”

The Discord incident follows a plethora of data breaches resulting from the compromise of third-party IT service providers in 2025. Groups such as Scattered Spider and ShinyHunters have been linked to a number of these attacks, which use social engineering techniques to obtain credentials of high-profile users.

Image credit: rafastockbr / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHow to Close Threat Detection Gaps: Your SOC’s Action Plan
Next Article Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware
Team-CWD
  • Website

Related Posts

News

Badges, Bytes and Blackmail

February 7, 2026
News

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026
News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Can password managers get hacked? Here’s what to know

November 14, 2025

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.