Messaging platform Discord confirmed that one of its third-party customer service providers was hacked, allowing an unauthorized party to access information from a limited number of users who had contacted Discord’s Customer Support and Trust & Safety teams.
In emails sent to affected users, the company said the compromised data included names, usernames, email addresses, and the last four digits of credit card numbers.
In a statement released on Friday, Discord stated that full card numbers and account passwords were not exposed. However, the unauthorized party also accessed a small number of government-issued ID images, such as passports and driver’s licenses, belonging to users who had appealed age determinations. The leaked information reportedly also included national ID details.
According to the company, the attackers demanded a ransom payment but did not gain direct access to Discord itself. With Discord’s monthly active user base exceeding 200 million globally, the breach is expected to affect millions of members worldwide.
If an individual’s government ID may have been accessed, that information will be specified in the notification, Discord said. The company has revoked the third-party provider’s access to its ticketing system, informed data protection authorities, engaged with law enforcement, and reviewed "threat detection systems and security controls for third-party support providers."
Business-focused Forbes claimed that the attack was carried out by a group known as Scattered Lapsus$ Hunters, which has previously been associated with data breaches at British companies, including Jaguar Land Rover and Marks & Spencer. Discord has not confirmed these allegations.
In its announcement, the company said users can contact customer support for additional information or assistance following the breach.
Discord has been banned in Türkiye and access has been restricted since October 2024 due to the platform’s alleged role in promoting illicit activities among young individuals, including child abuse, sexual harassment, and fraud.