[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2pwnbc2wb9ewl":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":37,"seoTitle":38,"seoTitleEn":39,"seoDescription":38,"seoDescriptionEn":40,"logoUrl":41,"isVerified":4,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"6a7177aa4ceb6fabc447a784","Discord5CA2025","Discord Data Breach","discord-5ca-2025","discord.com","2025-09-20T00:00:00.000Z","2026-08-04T05:24:58.511Z","Discord official notice, Texas Attorney General, and BleepingComputer","https:\u002F\u002Fdiscord.com\u002Fpress-releases\u002Fupdate-on-security-incident-involving-third-party-customer-service",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdiscord-discloses-data-breach-after-hackers-steal-support-tickets\u002F",74729,"known",null,"people","Medium",[24,25,26,27,28,29,30,31,32,33,34,35,36],"Names","Usernames","Email addresses","Contact information","Physical addresses","Dates of birth","IP addresses","Partial credit card data","Purchase history","Customer support tickets","Government issued IDs","Driver's license numbers","Passport numbers","\u003Cp>\u003Cstrong>The 2025 Discord data breach\u003C\u002Fstrong> involved unauthorized access on September 20, 2025 to a system operated by 5CA, a third-party provider used for Discord customer service. The Texas Attorney General record reports 74,729 affected people nationwide.\u003C\u002Fp>\u003Cp>The incident was limited to certain users who had communicated with Discord Customer Support or Trust &amp; Safety. Discord described it as a breach of its third-party customer-service provider rather than its core platform.\u003C\u002Fp>\u003Ch2>When did the Discord data breach occur?\u003C\u002Fh2>\u003Cp>The Texas Attorney General record and notices sent to affected users identify September 20, 2025 as the unauthorized-access date. The regulator record says the incident was discovered on September 25; Discord published its notice on October 3 and updated it on October 9.\u003C\u002Fp>\u003Cp>Discord said the unauthorized party targeted the third-party support service with the goal of extorting a ransom. Public documents do not disclose the technical initial-access method.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>Texas Attorney General record BR-0004706 reports 74,729 affected people nationwide, including 1,465 Texas residents. The Texas figure is part of the national total and has not been added again.\u003C\u002Fp>\u003Cp>Discord separately said that approximately 70,000 users may have had government-ID photos exposed after submitting them for age-related appeals. This is not the total user count; it is a sensitive subset of the 74,729-person incident.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>Discord said the data may have included names, Discord usernames, email and other contact details provided to support, IP addresses, messages and attachments shared with customer-service agents, payment type, the last four payment-card digits, and purchase history. Government-ID images such as driver's licenses or passports were involved for some users.\u003C\u002Fp>\u003Cp>The Texas record also lists addresses and dates of birth. Fields may have varied by person. Discord said full card numbers and security codes, passwords, authentication data, and Discord messages or activity outside support conversations were not involved.\u003C\u002Fp>\u003Ch2>What risks can this incident create?\u003C\u002Fh2>\u003Cp>ID images, birth dates, and addresses can support identity theft or fraudulent account applications. Email addresses, usernames, and support history can also make phishing messages impersonating Discord appear more credible.\u003C\u002Fp>\u003Cp>Support messages and attachments may contain different details for each person. The last four card digits alone cannot authorize a full payment, but combined with purchase and support context they can be used in false refund, subscription, or account-recovery requests.\u003C\u002Fp>\u003Ch2>How did Discord respond?\u003C\u002Fh2>\u003Cp>Discord said it revoked 5CA's access to the support-ticket system, launched an internal and forensic investigation, engaged law enforcement, and notified relevant data-protection authorities. It also reviewed auditing and security controls for third-party support providers.\u003C\u002Fp>\u003Cp>Discord said affected users would be contacted only by email from \u003Cstrong>noreply@discord.com\u003C\u002Fstrong> and that it would not call about this incident. A caller asking for information or payment is therefore inconsistent with Discord's official notice.\u003C\u002Fp>\u003Ch2>What should affected users do?\u003C\u002Fh2>\u003Cp>Users told that an ID image may have been involved should follow the country-specific steps in their notice and consider credit monitoring, a fraud alert or credit freeze, and contacting the issuing authority when appropriate.\u003C\u002Fp>\u003Cp>Notice recipients should review card and purchase activity for unfamiliar transactions and go directly to Discord's official app or website rather than following links in unexpected support or recovery messages. Passwords were not in the reported scope; however, change a password if it was entered on a fraudulent page or reused elsewhere.\u003C\u002Fp>","","Discord Data Breach (74.7 Thousand People Affected)","Discord's third-party support breach affected 74,729 people. Review the identity, contact, billing, and support data involved and practical protection steps.","\u002Fuploads\u002Flogo\u002Fdiscord.svg",false,{"name":44,"sector":45,"country":46,"website":47,"websiteArchiveUrl":38,"websiteStatus":48,"websiteCheckedAt":12},"Discord Inc.","Social Media","United States","https:\u002F\u002Fdiscord.com\u002F","active"]