Discord has confirmed a new breach involving one of its customer support contractors: on September 20, 2025, an intruder accessed information concerning a “limited” number of users who had interacted with Support or Trust & Safety.

Discord has confirmed a new breach involving one of its customer support contractors: on September 20, 2025, an intruder accessed information concerning a “limited” number of users who had interacted with Support or Trust & Safety. The platform clarified that its own systems were not penetrated and that the incident was confined to the service provider; the attacker allegedly attempted extortion. Notifications are being sent to affected individuals, with details of the scope provided for each person.

The information accessed included names, usernames, email addresses and, in some cases, the last four digits of bank cards. More sensitive still, a “small number” of identity documents submitted for age verification—including national ID cards, passports and driving licences—were reportedly copied. Discord stated that no passwords or full card numbers were exfiltrated; private messages are not affected, except for content shared in support tickets. Several technology media outlets have corroborated the timeline and the categories of data mentioned.

In practical terms, users who contacted support are advised to watch for potential phishing emails, change passwords reused elsewhere, cancel linked cards if there is any concern and, for those who submitted an identity document, request an alert or a precautionary freeze depending on their jurisdiction. Discord said it has cut off the service provider’s access, notified the authorities and strengthened its third-party controls. This episode has revived the debate over age verification and data minimization, an issue already highlighted by the specialist press. Investigations and official updates are still expected to clarify the actual scale.