Discord, the popular communication platform, recently made a significant, yet silent, update to its press release concerning a security incident, clarifying the nature of the breach and who was responsible. The updated notice, dated October 9, 2025, now explicitly names the compromised party as 5CA, a third-party service provider (commonly referred to as a Business Process Outsourcing or BPO firm) that Discord used to support its customer service efforts. Initially, the company only referred to a "third-party vendor" being compromised. The decision to name the BPO publicly is a notable move towards greater transparency, answering the question of which external partner was involved and explicitly assigning a name to the security failure. Discord maintains that the incident was a breach of 5CA's systems, not Discord’s own network. According to Discord’s press release, the incident impacted a limited number of users who had communicated with the Customer Support or Trust & Safety teams. The most critical exposure involves the government-ID photos of approximately 70,000 users globally, which the vendor used to review age-related appeals. Other exposed data includes: Name, Discord username, email, and other contact details provided to customer support. Limited billing information (payment type, last four digits of the credit card, purchase history). IP addresses. Messages exchanged with customer service agents. Discord states it immediately revoked 5CA's access to its ticketing system, launched an internal investigation, and is working with law enforcement. The public naming of the BPO is likely a result of legal and regulatory requirements for disclosure, particularly given the sensitive nature of the exposed government-ID information.
Published by Banx Network. This article is part of the Banx decentralized media programme, powered by the BXE token on the XRP Ledger.




