Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    DeSantis Pushes Aggressive State AI Regulation With AI Bill of Rights and Data Center Limits

    February 9, 2026

    Lawmakers, Parents Renew Push To Sunset Section 230 And Make Big Tech Liable

    February 9, 2026

    Slovenia Proposes Ban On Social Media For Under-15s Amid Growing Global Push

    February 8, 2026
    Facebook X (Twitter) Instagram
    • Tech
    • AI News
    • Get In Touch
    Facebook X (Twitter) LinkedIn
    TallwireTallwire
    • Tech

      Lawmakers, Parents Renew Push To Sunset Section 230 And Make Big Tech Liable

      February 9, 2026

      NASA Clears Smartphones for Artemis Moon Mission

      February 7, 2026

      SpaceX Acquires xAI in Record-Setting Merger, Pivots Toward Space-Based AI Data Centers

      February 7, 2026

      Iran’s Government Blackout of the Internet Amid Protests Stifles Communication and Masks Violence

      February 6, 2026

      Israeli Aerospace Startup Unveils Heavy-Lift Cargo Drone at Singapore Airshow

      February 6, 2026
    • AI News

      DeSantis Pushes Aggressive State AI Regulation With AI Bill of Rights and Data Center Limits

      February 9, 2026

      EU Drove Global Censorship Through Tech Platforms: House Judiciary Report

      February 8, 2026

      China’s Porn Spam Tactic on X Draws Red Flags Over Digital Censorship

      February 8, 2026

      Amazon Begins Closed Beta Testing of AI Tools to Reshape Film and TV Production

      February 8, 2026

      European University Offline for Days After Major Cyberattack Disrupts Systems

      February 7, 2026
    • Security

      EU Drove Global Censorship Through Tech Platforms: House Judiciary Report

      February 8, 2026

      Slovenia Proposes Ban On Social Media For Under-15s Amid Growing Global Push

      February 8, 2026

      NSW Moves to Make Employers Liable for AI and Digital System Harms Under Work Safety Law

      February 8, 2026

      Hackers Dump Millions of Harvard and UPenn Records After Refused Ransom Demands

      February 8, 2026

      European University Offline for Days After Major Cyberattack Disrupts Systems

      February 7, 2026
    • Health

      AI Technology Offers Early Warning System for Deadly Coral Bleaching

      February 6, 2026

      Israel’s New Soreq B Desalination Plant Reaches Full Operational Capacity Boosting Water Supply

      February 3, 2026

      Institutions Are Missing AI’s Potential For Drug Discovery, Experts Say

      February 2, 2026

      Landmark Legal Battles Ignite Over Alleged Social Media Addiction Impacting Youth and Schools

      February 1, 2026

      OpenAI Deploys Free AI-Powered Scientific Workspace Prism to Reshape Research

      January 31, 2026
    • Science

      Pacific Fusion Advances Cheaper Path to Fusion Through Sandia Reactor Experiments

      February 8, 2026

      Trump’s Critical Minerals Reserve Signals U.S. Adapts to Electric Future Amid China Competition

      February 7, 2026

      NASA Clears Smartphones for Artemis Moon Mission

      February 7, 2026

      Elon Musk Pushes Forward With Orbital Data Center Ambitions

      February 7, 2026

      AI Technology Offers Early Warning System for Deadly Coral Bleaching

      February 6, 2026
    • People

      Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

      February 7, 2026

      Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

      February 6, 2026

      Informant Claims Epstein Employed Personal Hacker With Zero-Day Skills

      February 5, 2026

      Starlink Becomes Critical Internet Lifeline Amid Iran Protest Crackdown

      January 25, 2026

      Musk Pledges to Open-Source X’s Recommendation Algorithm, Promising Transparency

      January 21, 2026
    TallwireTallwire
    Home»Tech»Discord Vendor Breach Puts 70,000 Users’ IDs at Risk Amid Extortion Claims
    Tech

    Discord Vendor Breach Puts 70,000 Users’ IDs at Risk Amid Extortion Claims

    Updated:December 25, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Discord Vendor Breach Puts 70,000 Users’ IDs at Risk Amid Extortion Claims
    Discord Vendor Breach Puts 70,000 Users’ IDs at Risk Amid Extortion Claims
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Discord disclosed that a third-party customer support vendor was breached, possibly exposing government ID photos and related personal data for about 70,000 users, though hackers claim the haul could be far larger (1.5 TB, 2.1 million IDs). Discord insists the estimates are exaggerated and refuses to pay extortion demands, while severing ties with the vendor (identified as 5CA) and working with authorities. Alongside the ID images, compromised data may include names, usernames, emails, IP addresses, messages with support, and limited billing details (e.g. last four digits of credit cards). Discord’s core systems, passwords, and full payment data were reportedly unaffected.

    Sources: The Verge, The Guardian

    Key Takeaways

    – The breach stemmed not from Discord itself, but through a compromised third-party support/age verification service (5CA).

    – Hackers claim a far larger incident (1.5 TB, millions of files) beyond Discord’s estimate of ~70,000 exposed ID photos.

    – Although core credentials, passwords, and full payment data are said to be safe, leaked identity documents and metadata pose serious long-term risks to affected users.

    In-Depth

    On October 3, 2025, Discord announced a serious security incident: an unauthorized party had compromised one of its third-party customer service vendors, 5CA, used for support and age verification workflows. Discord clarified that its internal systems were not breached, but a subset of users who communicated with support or appealed age blocks may have had sensitive data exposed. In its statement, Discord estimated that about 70,000 users could have had government ID images accessed, along with auxiliary data like names, usernames, emails, IP addresses, support messages, and limited billing info (such as card type or last four digits). The company says no passwords, full credit card numbers, or private Discord messages were compromised.

    In parallel, hacker groups behind the breach have claimed that the scale is much larger: posting screenshots of support tickets, dashboards, and asserting that 1.5 terabytes of data—including 2.1 million government ID images—were stolen. Discord strongly disputes those numbers, calling them extortion-driven exaggerations. Discord has since revoked the vendor’s system access, launched forensics investigations, notified affected users via email, and engaged law enforcement and data protection authorities.

    This incident underscores a growing weak point in modern tech: third-party vendors. Even when a platform’s own defenses are robust, outsourcing support, age checks, or identity verification to external firms introduces additional risk. In this case, the exposure is especially sensitive—government-issued identity documents (driver’s licenses, passports) cannot be changed like passwords or credit cards. Once leaked, that data can fuel identity theft, synthetic identity fraud, phishing, and long-term risks to the users involved.

    Moreover, the incident raises serious questions about mandatory age verification systems, especially in regulatory regimes that require platforms to validate user ages via ID checks (as is the case in the U.K.’s Online Safety Act). Critics warn that forcing platforms to collect and retain identity documents centralizes dangerous amounts of private data in places that become targets for attackers.

    For users, the immediate steps are clear: monitor financial accounts, enable identity theft protections, watch for phishing, and be wary of unsolicited contact claiming to relate to the breach. For platforms, the lesson is sharper: vet, audit, and secure vendor practices just as tightly as your own systems. The chain is only as strong as its weakest link—and in this case, the vendor link may have become the most dangerous one.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDigital Sovereignty Gets a Home Upgrade: SAP Launches On-Site Sovereign Cloud Model
    Next Article Disney Forces Character.AI to Pull Its Characters After Legal Warning

    Related Posts

    Lawmakers, Parents Renew Push To Sunset Section 230 And Make Big Tech Liable

    February 9, 2026

    NASA Clears Smartphones for Artemis Moon Mission

    February 7, 2026

    SpaceX Acquires xAI in Record-Setting Merger, Pivots Toward Space-Based AI Data Centers

    February 7, 2026

    Iran’s Government Blackout of the Internet Amid Protests Stifles Communication and Masks Violence

    February 6, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Lawmakers, Parents Renew Push To Sunset Section 230 And Make Big Tech Liable

    February 9, 2026

    NASA Clears Smartphones for Artemis Moon Mission

    February 7, 2026

    SpaceX Acquires xAI in Record-Setting Merger, Pivots Toward Space-Based AI Data Centers

    February 7, 2026

    Iran’s Government Blackout of the Internet Amid Protests Stifles Communication and Masks Violence

    February 6, 2026
    Top Reviews
    Tallwire
    Facebook X (Twitter) LinkedIn Threads Instagram RSS
    • Tech
    • Entertainment
    • Business
    • Government
    • Academia
    • Transportation
    • Legal
    • Press Kit
    © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

    Type above and press Enter to search. Press Esc to cancel.