Skip to content
LIVE
Loading prices...
Discord responds following sudden security breach

A mask in the dark

Discord responds following sudden security breach

Following a security breach affecting a third-party customer service provider, Discord has assured users of safety and provided updates on measures to secure their data.

Ad

The platform stated in an October 3 press release that the incident involved an unauthorized party that compromised one of its third-party customer service providers. 

Through the hack, the attacker gained access to information from some users with the intention of using their data to extort the company for ransom.

Scope of the attack

The attack targeted some users who had contacted Discord through the customer support and/or trust & safety teams. 

Ad

Data leaked included name, Discord username, email, and other contact details provided to Discord customer support.

The information also included some billing information such as payment type, the last four digits of their credit cards, and purchase history if associated with their accounts.

Others are IP addresses, messages with customer service agents, and limited corporate data such as training materials and internal presentations.

Users who had appealed an age determination may have also lost government‑ID images such as driver’s licenses and passports to the attacker.

The company noted that the attacker did not directly hit Discord in any way, and only the third-party customer service provider was affected.

Discord swings into action

After discovering the breach, Discord said it took immediate action by revoking the customer support provider’s access to their ticketing system.

The team also launched an internal investigation, engaged a computer forensics firm to support the investigation and remediation efforts, and also brought law enforcement onboard.

In addition, the company is sending emails to affected users which include details of information they have lost and the extent of damage done.

Affected users are warned to stay vigilant and only treat emails sent through the official Discord email address as genuine and worthy of attention to prevent further exploits.

How do you rate this article?

Join our Socials

Briefly, clearly and without noise – get the most important crypto news and market insights first.