.The Incident: Discord confirmed a data breach involving a third-party customer service provider (identified by attackers as Zendesk, and by Discord as 5CA in a press release) that handles customer support. Discord's core systems were not breached. The Attackers' Claims (The quote you provided): Threat actors, including the group believed to be Scattered Lapsus$ Hunters (or another interconnected group), claimed to have compromised the Zendesk instance and stolen 1.5 TB of age verification photos, totaling over 2.1 million images (implying 2.1 million user IDs). The attack was for the purpose of extorting a ransom from Discord. Discord's Official Confirmation: Discord publicly addressed these claims, stating the numbers were "incorrect and part of an attempt to extort a payment." Discord confirmed that the exposed sensitive data included government ID photos for an approximately limited number of 70,000 users globally who had submitted them for age-related appeals. Other Exposed Data: For users who interacted with customer support, the exposed data may also have included: Names, Discord usernames, and email addresses. IP addresses. Messages exchanged with customer service. Limited billing information (payment type, last four digits of credit cards). Some internal corporate documents. Data NOT Exposed: Discord confirmed that no passwords, full credit card numbers, CVV codes, or private in-app messages outside of support communications were accessed. Discord's Response: The company immediately revoked the vendor's access, launched an internal investigation with forensic experts, and involved law enforcement. They are notifying all affected users via email from noreply@discord.com.
Published by Banx Network. This article is part of the Banx decentralized media programme, powered by the BXE token on the XRP Ledger.




