discord-support-vendor-2025 · Disclosed 2025-10-03
Discord: support-provider compromise exposed ticket information
Discord reported unauthorized access to support information through a provider compromise. About 70,000 users potentially had identity-document photos exposed; this is not a confirmed image-leak count.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Discord attributed the compromise to service provider 5CA and distinguished it from a breach of Discord itself.
[s1]TL;DR / What happened? - Reported fact
Support data and some identity images were affected; Discord said other chats, passwords, and authentication data were not involved.
[s1]What data was involved? / What data was not involved?
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Discord revoked provider access, engaged forensic specialists, and reported notifying affected users.
[s1]TL;DR / What are we doing about this?
Evidence relevant to prevention
Insufficient evidence
Inspect provider ticket permissions, attachment access logs, and identity-image retention; this notice does not establish the initial entry technique.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Initial cause, specific vulnerabilities, and confirmed victim count are unresolved; provider attribution reflects Discord’s statement.
Sources
[s1] Discord · Primary source
Update on a Security Incident Involving Third-Party Customer Service ↗Published 2025-10-03 · Reviewed 2026-10-02