Discord has confirmed that official ID photos and other personal data belonging to tens of thousands of users may have been exposed following a cyber-attack targeting one of its third-party service providers.
The messaging platform, which hosts more than 200 million users globally, said the incident affected a customer service firm responsible for handling age-verification and support requests. Discord stressed that its own systems were not breached.
In a press release, the San Francisco-based company said hackers had gained access to information from a “limited number of users” who had contacted its customer support or trust and safety teams. The compromised data may include names, Discord usernames, email addresses, IP addresses, partial billing information, and copies of messages exchanged with Discord’s agents.
The company added that approximately 70,000 users globally may have had government-issued ID photos exposed, which its vendor had used to review age-verification requests. “If your ID may have been accessed, that will be specified in the email you receive,” Discord told users.
The firm emphasised that no passwords, authentication tokens, or messages and activity beyond customer service conversations were affected. It also said no full credit card details or CCV codes were exposed.
“All impacted users have been contacted and Discord is working with law enforcement to investigate the matter,” the company said. The platform has revoked the compromised provider’s access to its systems and launched an internal investigation, supported by a computer forensics firm.
According to Discord, the attackers had sought to extort payment. A spokesperson told the BBC that online claims suggesting the breach was larger than reported were “inaccurate” and “part of an attempt to extort payment”. They added: “We will not reward those responsible for their illegal actions.”
Discord said it has notified data protection authorities and is reviewing its security controls and threat-detection systems for third-party providers. The company urged users to remain cautious of suspicious messages and confirmed that official communications would only come from the address noreply@discord.com.
The breach comes amid increasing global scrutiny over online age-verification laws, which have prompted platforms like Discord to collect sensitive personal data. Earlier this year, the company began rolling out facial age-assurance checks in the UK and Australia to comply with tightening regulations.
Recommended reading
- ICO Issues Guidance on Facial Recognition Technology
- Google Changes AI Policy to Work on Weapons and Surveillance
- UK Police Use of Facial Recognition Found to be ‘Unethical’
Under the UK’s Online Safety Act, which came into force in July 2025, platforms must take reasonable steps to prevent minors from accessing harmful material, including pornography and violent or abusive content. In Australia, a new “under-16 social media ban” will come into effect on 10 December, requiring multiple verification methods and formal appeal processes for users incorrectly flagged.
While Discord says images submitted for automated age verification are “deleted directly after” confirmation, its website notes that when automated checks fail, documents may be manually reviewed by staff – creating a potential vulnerability, as demonstrated in this breach.
“Protecting the privacy and security of our users is a top priority,” the company said. “We take our responsibility to protect your personal data seriously and understand the inconvenience and concern this may cause.”





