Drooid Logo
Back to story perspectives

Full Breakdown

Discord Data Breach Exposes Government ID Photos of 70,000 Users

10/10/2025, 4:40:45 AM

Overview of the Incident

Discord, a popular messaging platform, has confirmed a significant data breach affecting approximately 70,000 users worldwide. The breach occurred through a third-party customer service provider responsible for managing age verification processes. Hackers gained unauthorized access to government ID photos, names, email addresses, and other personal information of users who had contacted Discord's Customer Support or Trust & Safety teams.

Details of the Breach

The incident was disclosed by Discord on October 3, 2025, following reports of a cyberattack that exploited vulnerabilities in the third-party vendor's systems. The hackers, identified as the group "Scattered Lapsus$ Hunters," claimed to have stolen 1.5 terabytes of data, including over two million verification photos, and threatened to extort Discord for a ransom. However, Discord clarified that the actual number of exposed government ID photos is around 70,000, refuting claims of a larger breach.

Discord emphasized that its own systems were not compromised during the incident. The company severed ties with the affected vendor and is cooperating with law enforcement and data protection authorities to investigate the breach.

Implications for Users

The exposure of government ID photos poses a substantial risk for identity theft, as these documents are difficult to replace. Cybersecurity experts have warned that such sensitive data can lead to various forms of fraud, including impersonation and blackmail. The breach highlights the vulnerabilities associated with age verification systems, which have become increasingly common due to legal requirements in various jurisdictions, including the UK’s Online Safety Act.

Official Statements & Responses

In a statement, Discord spokesperson Nu Wexler addressed the breach, stating, “This was not a breach of Discord, but rather a third-party service we use to support our customer service efforts.” Wexler also noted that the company would not comply with the hackers' ransom demands, asserting, “We will not reward those responsible for their illegal actions.” Discord has contacted all affected users via email and is advising them to remain vigilant against potential phishing attempts.

Criticism & Opposition

Critics have raised concerns about the security practices of companies that outsource sensitive data management. Nathan Webb, a principal consultant at Acumen Cyber, described the breach as “very concerning,” emphasizing that businesses must ensure that third-party vendors uphold stringent data protection standards. The incident has sparked discussions about the necessity and safety of mandatory age verification processes that require users to submit personal identification.

Conflicting Reports & Gaps

While Discord maintains that approximately 70,000 users were affected, some reports from the hacker group suggest that the number of compromised IDs could be as high as two million. This discrepancy raises questions about the accuracy of the data reported and the extent of the breach.

What's Next

Discord is actively investigating the breach and has engaged external security experts to assess the situation. The company is also working to enhance its security measures to prevent similar incidents in the future. Users are advised to monitor their accounts for unusual activity and to take precautions to protect their personal information.

Verbatim Quotes

  • “This was not a breach of Discord, but rather a third-party service we use to support our customer service efforts.” — Nu Wexler, Discord Spokesperson
  • “We will not reward those responsible for their illegal actions.” — Nu Wexler, Discord Spokesperson
  • “A substantial risk for identity theft” — Cybersecurity Expert

This incident serves as a stark reminder of the potential vulnerabilities associated with digital identity verification and the importance of robust data protection practices.