[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3o9f0yu9lcb67":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":12,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":34,"seoTitle":35,"seoDescription":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a45548e116547d3d9ce5f47","restorecord","Restorecord Data Breach","restorecord.com","2024-02-01T00:00:00.000Z","2026-07-01T17:55:25.542Z",null,"2026-09-17T16:26:11.191Z","2026-07-19T00:03:55.373Z","Third party breach","https:\u002F\u002Frestorecord.com\u002F",[16,18],"https:\u002F\u002Fheroic.com\u002Fbreaches\u002Frestorecord",836097,"known","unknown","en",[22,24],"tr",{"en":26,"tr":27},{"slug":7},{"slug":7},"High",[30,31,32,33],"Discord usernames","Discord IDs","IP addresses","Last activity dates","\u003Cp>The Restorecord data breach record is a security incident that came to light in early 2024 and is associated with approximately 836,000 records. The record, linked to the backup and recovery service for Discord servers, contains platform identities and IP fields. This statement has been prepared to clarify which data fields of the user may be at risk, the verification limits of the incident, and the applicable security steps.\u003C\u002Fp>\u003Cp>When the Discord username, user ID, IP address, and last activity date are found together, community membership and connection information can be matched. Only data classes compatible with the available record are used in the text; unverified technical details, different events, or similarly named services are not presented as definite information under this record. This way, the user can see real risks without exaggeration but without leaving anything out.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this record are as follows: Discord usernames, Discord IDs, IP addresses, and last activity dates. Platform ID and IP address can increase the risk of targeted messaging or harassment in the context of server membership. When these fields are used together, fake notifications, account recovery, targeted search, identity correlation, or fraud attempts can become more convincing.\u003C\u002Fp>\u003Cp>This record does not list a password or email field; it arises from the risk platform ID, IP, and activity date. Even in records without a password, fields such as phone, address, IP, device information, work profile, membership, or physical location alone can pose significant risk. If there is a password or password-like field, it should also be checked whether the same information is repeated on different services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record is limited to approximately 836 thousand records associated with the domain restorecord.com. The incident is in the unverified record category. The scope has been written by separately evaluating the domain name, sector, country, number of accounts, data classes, and the possibility of overlap with similar incidents. Data types not listed have not been shown to the user as if they exist.\u003C\u002Fp>\u003Cp>Since the source of the record provided limited verification, definitive company violation language was not used. In records with verification limits, the text was not structured as if it were a definitive company statement. In records that may be duplicates or resemble a sub-event of another brand, this distinction is indirectly shown to the user and the data fields are not unnecessarily expanded.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Members of servers using Restorecord, whose Discord ID and IP address match, are at risk. The main risk for these people is that the leaked areas are matched with information used in other accounts. If the same email, phone, username, IP, address, social profile, or password is repeated across different accounts, the attack surface increases.\u003C\u002Fp>\u003Cp>The Discord context can be used in fake server invites, account verification, bot authorization, or community messages. Media, real estate, telecommunications, logistics, gaming, video, Discord services, dating platforms, and professional data contexts generate different risks. The user should consider not only the data fields but also which service context these fields are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check the security of their Discord accounts, connected applications, and server permissions. If a password or password-like field has been listed, users should change it on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication wherever possible. The email account should also be checked.\u003C\u002Fp>\u003Cp>In records containing phone, address, location, IP, device, work profile, billing, contract, or platform ID, users should check account recovery options, session history, forwarding rules, and suspicious messages. In corporate accounts, this information should be shared with the security team.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unnecessary permissions should be removed in Discord bots, third-party bots should be regularly reviewed, and strong verification should be used on accounts. In the long term, password manager, unique passwords, multi-factor authentication, closing old accounts, and deleting unnecessary profile fields are the basic defenses. Since permanent personal data cannot be recovered, account behavior and verification processes should be strengthened.\u003C\u002Fp>\u003Cp>From the perspective of institutions, these events show that data minimization, third-party access, the retention period of customer records, employee documents, and the regular auditing of incident reporting processes are necessary. On the user side, not repeating the same identity information across different services permanently reduces risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check the Discord account, connected bot permissions, and suspicious server invites. If a match is seen, the user should first read which data fields are listed and then prioritize the steps accordingly. If there is a password, password change should be prioritized; if there is an address or phone, a fraud alert; if there is an IP or device, session control; if there is sensitive membership, privacy control should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: Although this record has not been verified, it has been flagged as sensitive community data because it contains an IP address and platform ID. The user should compare this record with their account history; they should separately check the services where they have used the same email, phone number, username, IP, address, or password. Any suspicious search, email, message, or account recovery notification should be considered higher risk after the incident.\u003C\u002Fp>","Restorecord Data Breach (836.1 Thousand Reported Records)","Restorecord Data Breach. 836.1 Thousand reported records are reported. Reported data: Discord usernames, Discord ids, IP addresses. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Frestorecord_official.ico",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":43,"websiteStatus":43,"websiteCheckedAt":12},"Restorecord","Discord Bot \u002F Server Recovery","United States",""]