Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted
## Data Breach at Discord's Third-Party Vendor
Data Breach at Discord's Third-Party Vendor
Discord has reported a data breach involving its third-party customer service provider, Zendesk. According to reports, threat actors have exfiltrated approximately 1.5 terabytes of sensitive data, which includes government-issued identification photos used for age verification.
The breach occurred on Wed, Sep 20, 2025, targeting Discord's customer support systems managed by an external vendor. The attackers accessed the system for 58 hours by compromising a support agent's account from an outsourced business process provider.
Discord confirms that around 70,000 users had their ID photos exposed, contrary to claims from the attackers who allege possession of 2,185,151 photos. The compromised information includes:
Names, Discord usernames, and email addresses Limited billing details such as payment type and the last four digits of credit card numbers Messages exchanged with customer service agents User IP addresses
Discord has reported a data breach involving its third-party customer service provider, Zendesk.
The breach's most significant impact involves the theft of government-ID images, such as driver's licenses and passports, submitted by users for age-related verification processes.
Discord has declared it will not pay the ransom demanded by the cybercriminals. The company has revoked the compromised vendor's access and terminated the partnership. An internal investigation is underway, with assistance from a digital forensics firm and collaboration with law enforcement and data protection authorities.
Discord is notifying affected users via email from [email protected] . The notification will specify if a user's government ID was part of the compromised data. Discord assures that full credit card numbers, passwords, and private messages were not exposed.
This incident underscores the risks associated with supply chain attacks, where attackers exploit vulnerabilities in third-party vendors. The situation is ongoing, and the potential release of the stolen data by the attackers remains a concern.
Based on reporting by Cyber Security News.
