Drooid Logo
Back to story perspectives

Full Breakdown

Discord Data Breach Exposes Government ID Photos of 70,000 Users

10/9/2025, 7:43:31 PM

Overview of the Incident

Discord, a popular messaging platform with over 200 million users, recently confirmed a significant data breach involving the exposure of government ID photos for approximately 70,000 users. The breach occurred not within Discord's own systems but through a third-party customer support provider, likely Zendesk, which was compromised by hackers. The attackers gained access to sensitive user data, including names, email addresses, and limited billing information, during interactions with Discord's Customer Support and Trust & Safety teams.

Details of the Breach

The breach was initially reported on October 3, 2025, when Discord disclosed that hackers targeted a third-party vendor responsible for age verification services. The unauthorized access reportedly lasted for 58 hours, during which the attackers claimed to have stolen 1.5 terabytes of data, including over 2.1 million government ID photos. However, Discord has firmly stated that only around 70,000 users had their ID photos exposed, asserting that the larger figures are part of an extortion attempt by the hackers.

  • Government-issued ID images (e.g., driver's licenses, passports)

Discord emphasized that full credit card numbers, passwords, and any messages beyond those with customer support were not compromised.

Official Statements & Responses

In response to the breach, Discord's spokesperson, Nu Wexler, stated, “This was not a breach of Discord, but rather a third-party service we use to support our customer service efforts. The numbers being shared are incorrect and part of an attempt to extort a payment from Discord. We will not reward those responsible for their illegal actions.” Discord has taken immediate steps to address the situation, including revoking the compromised vendor's access to its systems and launching an internal investigation with law enforcement assistance.

Criticism & Opposition

Despite Discord's assurances, some cybersecurity experts and commentators have raised concerns about the adequacy of the company's data protection measures, particularly regarding the retention of sensitive information like government IDs. Critics argue that the incident highlights vulnerabilities associated with third-party services, which can expose user data even when the primary platform remains secure. Additionally, there are ongoing discussions about the implications of age verification laws that necessitate the collection of such sensitive data.

Conflicting Reports & Gaps

While Discord maintains that only 70,000 users were affected, the hackers claim to have accessed data from 5.5 million users, including 2.1 million ID photos. This discrepancy raises questions about the true extent of the breach and the potential risks for users. The attackers have threatened to release the stolen data if their ransom demands are not met, further complicating the situation.

What's Next

Discord is actively notifying affected users and advising them to remain vigilant against potential phishing attempts. The company is collaborating with law enforcement and data protection authorities to investigate the breach and enhance its security measures. As the situation develops, users are encouraged to monitor their accounts for suspicious activity and to utilize multi-factor authentication for added security.

Verbatim Quotes

  • “This was not a breach of Discord, but rather a third-party service we use to support our customer service efforts.” — Nu Wexler, Discord Spokesperson
  • “Second, the numbers being shared are incorrect and part of an attempt to extort a payment from Discord.” — Nu Wexler, Discord Spokesperson
  • “We will not reward those responsible for their illegal actions.” — Nu Wexler, Discord Spokesperson

This incident underscores the importance of robust cybersecurity practices, particularly when sensitive user data is involved, and highlights the risks associated with third-party service dependencies.