Discord Data Breach Exposes 1.5 TB of Data and 2 Million Government ID Photos
## Discord Security Breach: Key Details and Impact
Discord Security Breach: Key Details and Impact
Discord, a widely used communication platform, has been affected by a data breach involving its third-party customer service provider. The breach resulted in unauthorized access to sensitive user data, including government identification photos used for age verification.
The attackers claim to have accessed 1.5 terabytes of sensitive data, including over 2.1 million government-issued identification photos. However, Discord has reported that the breach affected approximately 70,000 users, exposing their ID photos during the incident on September 20, 2025.
The breach did not directly target Discord's infrastructure but occurred through compromised customer support systems managed by Zendesk, a third-party vendor. Attackers gained unauthorized access for 58 hours by exploiting the account of a support agent from an outsourced business process provider.
User names and Discord usernames Email addresses Limited billing information, including payment methods and the last four digits of credit card numbers Customer service message exchanges User IP addresses
Discord, a widely used communication platform, has been affected by a data breach involving its third-party customer service provider.
Notably, government identification images, such as driver's licenses and passports, were also compromised, primarily affecting users who contacted Discord's Customer Support or Trust & Safety teams.
Discord has refused to pay the ransom demanded by the attackers and has terminated its partnership with the compromised vendor. The company has revoked all vendor access to its ticketing systems and initiated an internal investigation.
Discord is working with a leading computer forensics firm, law enforcement, and data protection authorities to address the incident. Users whose government IDs were compromised will receive notifications via official email channels.
This incident highlights the vulnerabilities in outsourcing customer service operations and the risks associated with storing sensitive verification documents. It also underscores the increasing threat of supply chain attacks, where cybercriminals target less secure third-party partners to access data from larger organizations.
Discord assures users that the breach did not expose complete credit card numbers, passwords, or private messages outside of customer support interactions.
Based on reporting by GBHackers.
