Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Discord Says User Information Stolen in Third-Party Data Breach

Names, usernames, email addresses, contact information, IP addresses, and billing information was compromised.

Social media platform Discord says hackers stole users’ personal information from one of its third-party customer service providers.

The incident, the company says, only affects users who contacted Discord through its “Customer Support and/or Trust & Safety teams”, and was limited to the third-party provider, with no Discord systems affected.

The compromised user information includes names, usernames, email addresses, contact information, billing information, IP addresses, messages exchanged with customer service agents, and limited corporate data.

For users who appealed age determination, government ID images were also compromised, Discord notes.

The platform says no financial information, Discord activity and messages, or passwords and other authentication data was compromised in the incident.

Discord has started notifying the affected users via email, has notified the relevant authorities, reviewed its threat detection systems, and took steps to address the data breach.

Advertisement. Scroll to continue reading.

“This included revoking the customer support provider’s access to our ticketing system, launching an internal investigation, engaging a leading computer forensics firm to support our investigation and remediation efforts, and engaging law enforcement,” the company explains.

Discord is advising the affected users to be wary of unsolicited messages or other communication that may seem suspicious.

The company has not shared details on when the incident occurred, which third-party service was involved, and how many users were affected. The company has over 200 million active monthly users.

Threat intelligence and research project Vx-Underground says the data breach occurred on September 20.

Some reports link the incident to the recent Salesforce extortion campaign attributed to the Scattered LAPSUS$ Hunters threat group, but Vx-Underground, which described the incident as a Discord Zendesk compromise, said Scattered LAPSUS$ Hunters is not behind the attack. Instead it’s a group that “does not have an attributed Threat Group name”.

SecurityWeek has emailed Discord for additional information on the incident and will update this article if the company responds.

“Our investigation indicates this incident did not arise from a vulnerability within Zendesk’s platform. Zendesk’s own systems were not compromised,” a Zendesk spokesperson told SecurityWeek.

*Updated with statement from Zendesk.

Related: Beer Giant Asahi Says Data Stolen in Ransomware Attack

Related: Hackers Extorting Salesforce After Stealing Data From Dozens of Customers

Related: Data Breach at Doctors Imaging Group Impacts 171,000 People

Related: 1.2 Million Impacted by WestJet Data Breach

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.