The website suffered a data breach on Monday, which exposed personal information of its roughly 760,000 users. As a result, the website issued a statement saying “we are stopping all operations for the foreseeable future.”
Members whose data was breached received a notification detailing what was compromised. The data includes mostly usernames, DiscordIDs, and emails. Some members had their billing addresses compromised, along with salted and hashed passwords.
Significantly, no financial information was compromised, as all payments are done through third party processors like PayPal.
The third party app only stored user IDs, and not the authentication token, so there is no need for the compromised accounts to change their passwords on the Discord app itself.
Discord.io allows users to send custom server invites to Discord channels. The compromise was attributed to a vulnerability in the website’s code, allowing the attacker to gain entry to the member database. The attacker then downloaded the complete database, and put it up for sale on BreachForums.
The company has since cancelled all active subscriptions, and pledged to reach out to affected members as soon as possible. The company has also said it plans to rebuild its website’s code from scratch, as well as conduct a complete overhaul of its security practices.
Recommended reading
- Discord Alerts Users of Data Breach, Urges Caution
- Instagram Loses 6M In Star Snap Hack
- Cloudflare Outage Brings Down Shopify, Fitbit, Doordash, and Other Services
“The data breach’s impact on user privacy and security cannot be understated. With the personal information of hundreds of thousands of individuals compromised, the potential for identity theft, phishing attacks, and other malicious activities is alarming,” said Erfan Shadabi, cybersecurity expert at comforte AG.
“In light of this incident, it becomes evident that a proactive and comprehensive approach to cybersecurity is imperative for organisations that manage sensitive user data,” he continued.





