Discord has revealed that one of its customer service providers has suffered a data breach. The attackers gained access to Government-ID images, and user details.
Discord doesn't actually mention when the breach took place, it only says it "recently discovered an incident". The fact that Government ID images were stolen is important, the U.K.'s Online Safety Act came into effect on July 25, 2025. So, that means the data breach happened sometime between then and October 3rd, when the news about the incident was revealed. It's also worth noting that the victim of the hack was a third-party customer service that has not been named.
As for the attack, the incident involved an unauthorized party compromising one of the messaging services' customer service providers, which in turn allowed the hackers access to limited customer data, pertaining to those who had contacted Customer Support and/or Trust & Safety teams. Discord says it revoked the breached service provider's access to its ticketing system. It is investigating the matter with the help of a computer forensics firm, and is working with law enforcement. Users who were impacted by the incident are being notified via an email that is sent from [email protected]
Here's what Discord says the hackers managed to access: Name, Discord username, email and other contact details that were provided to customer support, billing information such as payment type, the last four digits of credit cards, and purchase history of the accounts, IP addresses, messages with customer service agents, and limited corporate data (training materials, internal presentations).
There was something else.
"The unauthorized party also gained access to a small number of government?ID images (e.g., driver's license, passport) from users who had appealed an age determination. If your ID may have been accessed, that will be specified in the email you receive."
The story continues:
Related Stories
Privacy is prerequisite for free thought, dissent, experimentation, and innovation, which are in turn prerequisites for democracy. At NBTV, Naomi Brockwell has posted four reasons why limits on privacy are absolutely not a price worth paying for mainstream adoption.
Today I participated in a Privacy Salon in Denver where we debated a proposition that cuts to the core of the modern privacy movement:
"Limits on privacy are a price worth paying for mainstream adoption of cryptographic privacy."
I was on the "no" side alongside Matt Green, with Evin McMullen and Wei Dai arguing "yes."
It was a lively, thoughtful exchange that forced us to confront a deeper question: is weakening privacy simply the cost of scale?
Below is my opening statement from the debate.
The false argument about having nothing to hide does not hold water. As Ed Snowden observed years ago, "arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say."
Previously:
(2026) Ring Cancels Flock Deal After Dystopian Super Bowl Ad Prompts Mass Outrage
(2026) Discord Will Require a Face Scan or ID for Full Access Next Month
(2026) "ICE Out of Our Faces Act" Would Ban ICE and CBP Use of Facial Recognition
(2025) Big Tech Wants Direct Access to Our Brains
(2025) Discord Customer Service Data Breached; Government-ID Images, and User Details Stolen
(2025) A Surveillance Vendor Was Caught Exploiting a New SS7 Attack to Track People's Phone Locations
... and many more
(Score: 4, Interesting) by Ox0000 on Sunday October 12 2025, @08:09AM
Meh, just another day, just another breach...
F'all will change because it's not the company's data that was breached, it's the data for its
cattleproductsmarksdamnit, I mean 'valued community members'.Here's the corporate communications playbook for how these kinds of events typically play out:
Now regardless of this particular breach, and I'm in no way intending to downplay the effects that this breach will have on those affected by it; I have a genuine question: why are gov issued IDs sensitive?
I have a hard time believing that it's because of the inherent data on them. This leads me to believe that it's sensitive because of how companies - specifically companies, not govs (govs are different) - are dealing with the data on those documents. It seems similar to me as how SSNs have become de-facto passwords in the US even though the SSA explicitly instructs that "SSNs should not be used as identifiers" on their web site.
To me, the problem is not the data on these documents or even the document itself, it's that the data on these documents is used as "some secret that will get you access to other data, money, or services".
The problem seems to reside in the usage of the data on these documents.
(Score: 3, Informative) by turgid on Sunday October 12 2025, @10:17AM (6 children)
They seem determined to give us this Digital ID single point of failure. Push back [bigbrotherwatch.org.uk].
I signed a petition, which was very popular. In the email reply, the TL;DR was essentially, "You're getting it whether you like it or not. Suck it up."
Push back more.
I refuse to engage in a battle of wits with an unarmed opponent [wikipedia.org].
(Score: 1, Touché) by Anonymous Coward on Sunday October 12 2025, @04:18PM (3 children)
Just another honeypot.
Wow.. just like the old Soviet days, everything is suspect, nothing is real
(Score: 3, Touché) by turgid on Monday October 13 2025, @07:58AM (2 children)
Yeah, we should just keep our heads down and let them do whatever they want... Nope.
I refuse to engage in a battle of wits with an unarmed opponent [wikipedia.org].
(Score: 0) by Anonymous Coward on Tuesday October 14 2025, @02:43PM (1 child)
Your vote means more than a petition. Bad governance is voted, not petitioned into being
(Score: 2) by turgid on Tuesday October 14 2025, @04:26PM
I vote as hard as I can. Petitions raise awareness.
I refuse to engage in a battle of wits with an unarmed opponent [wikipedia.org].
(Score: 2) by darkfeline on Tuesday October 14 2025, @08:22PM (1 child)
The UK seems determined to make V for Vendetta a reality. Maybe High Chancellor Starmer is a fan
Join the SDF Public Access UNIX System today!
(Score: 2) by turgid on Tuesday October 14 2025, @08:26PM
I've never seen that. I need to watch it.
I refuse to engage in a battle of wits with an unarmed opponent [wikipedia.org].