Discord disclosed a September 2025 security incident involving 5CA, a third-party customer-service provider. Discord says the incident affected a limited set of support-related records—not its core platform—and that approximately 70,000 users may have had government-ID photos exposed. Other potentially accessible data included support messages, names, usernames, email addresses, IP addresses and limited billing details.
That distinction matters: Discord has not said that its entire account database, private server messages, passwords or authentication tokens were breached.
Was Discord itself hacked?
Discord said an unauthorized party compromised services operated by 5CA, the vendor supporting some Discord customer-service operations. The affected environment could contain information submitted to Discord Customer Support or Trust & Safety. Discord revoked the vendor’s access, began a forensic investigation and contacted law enforcement. Its official disclosure describes this as a third-party customer-service incident, not a compromise of Discord’s core messaging infrastructure.
The relevant source is Discord’s October 3, 2025 announcement and October 9 update: Discord’s security-incident update.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
What happened and when?
- September 20, 2025: A later court complaint alleges that data was acquired from Discord’s third-party support services on or about this date. That date is an allegation in a complaint, not a court finding: Uceta v. Discord complaint.
- October 3, 2025: Discord publicly disclosed the vendor compromise and said it had started an investigation.
- October 9, 2025: Discord updated its estimate, saying approximately 70,000 accounts may have had government-ID photos exposed.
- October 2025 onward: Larger attacker claims circulated online. Discord disputed those claims and characterized them as inaccurate and part of an extortion attempt.
What information may have been exposed?
| Potentially accessible in the support environment | Discord said was not involved |
|---|---|
| Names and Discord usernames | Passwords |
| Email addresses and other contact details supplied to support | Authentication data or tokens |
| IP addresses | Full credit-card numbers |
| Messages exchanged with customer-service agents | Card-security (CVV) codes |
| Payment type, card last four digits and associated purchase history | Discord messages and activity outside Customer Support or Trust & Safety interactions |
| Government-ID images for approximately 70,000 users, according to Discord | — |
All categories in this table come from Discord’s incident statement. “Potentially accessible” does not mean every record was copied, published or misused.
How to interpret the risk
- An email address, username and support conversation can make convincing phishing or impersonation easier.
- An IP address can indicate a network and approximate location; it is not automatically a precise home address or an account password.
- Four card digits and purchase history can help social engineering, but cannot recreate a full payment card on their own.
- An identity-document image is the most serious category because it may support impersonation or attempts to bypass identity checks. It cannot be “reset” like a password.
Who was potentially affected?
The strongest confirmed risk group is people who contacted Discord Customer Support or Trust & Safety and supplied personal, billing, IP or identity information in a ticket. This includes some age-related appeals and verification cases handled through the affected support environment.
Having a Discord account alone does not establish exposure. Discord has not published a universal self-service lookup for every user; it said affected people would be contacted by email.
Two figures that should not be combined
Discord said approximately 70,000 users may have had government-ID photos exposed. Separately, a Wisconsin breach listing reports 5.6 million individuals in connection with the broader 5CA incident: Wisconsin breach-notification listing. That vendor-level figure is not evidence that 5.6 million Discord users—or 5.6 million Discord ID documents—were exposed.
Recommended Free Tools
How to verify a real Discord notification
Discord says incident notices come by email from [email protected] and that it will not call users about this incident: official notice details. Sender names can be forged, so:
- Inspect the complete sender address and the destination of every link.
- Be suspicious of urgent threats, attachments or requests for payment.
- Never provide a password, one-time code, full card number or new ID image in response to an unsolicited message.
- Open Discord or its support center by typing the address yourself rather than using an email link.
What to do now
1. Check whether you used Discord support
Search old support emails and Trust & Safety tickets, including account-recovery, moderation, billing and age-related appeals. Look for attachments or identity documents you uploaded. A support interaction identifies a possible risk group; it does not prove that your record was accessed.
2. Secure your Discord account when indicated
Discord says passwords and authentication data were not involved in this incident, so a password reset is not required solely because of the vendor event. Change your password immediately if you see suspicious activity, reused the password elsewhere, clicked a suspicious link, installed untrusted software or received an account-compromise notice. Use a unique password, enable two-factor authentication, review authorized apps and connected accounts, check for an unexpected email change and warn contacts if your account sent unusual messages.
Use Discord’s official recovery guidance if the account may be compromised: My Discord Account was Hacked or Compromised. Discord also says staff will not request passwords or payment through in-app direct messages.
3. Monitor payment accounts
Discord says full card numbers and CVV codes were not involved. Turn on transaction alerts and review statements. Contact the card issuer if a charge is suspicious. For a disputed Discord transaction, contact Discord Billing before initiating a bank chargeback; Discord warns that a direct dispute can lead to account suspension while it investigates: Discord’s unauthorized-transaction guidance.
Rank #4
4. Respond to an exposed-ID notice
If your official notice specifically says a government-ID image was involved, preserve the notice and related correspondence. Consider placing a free credit freeze with each major U.S. credit bureau or a fraud alert, monitor credit reports and financial accounts, and watch for tax, benefits, employment, telecom or new-account fraud. Report suspected identity theft through the appropriate government identity-theft service. Ask the notice’s contact channel whether you qualify for identity restoration or monitoring. The Wisconsin listing mentions 12 to 24 months of monitoring for the broader 5CA matter, but that does not establish a universal Discord benefit for every user.
5. If you clicked a suspicious breach email
Change any password entered on the page, starting with the affected account and then other accounts where it was reused. Revoke unfamiliar sessions or connected apps, enable two-factor authentication and contact your email provider or financial institution if credentials or payment details were submitted. Run a security scan if you downloaded a file.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is confirmed, and what remains unverified?
- Confirmed by Discord: 5CA’s customer-service environment was compromised; support-related data may have been accessed; approximately 70,000 users may have had ID photos exposed; Discord revoked access and investigated with specialists and law enforcement.
- Not established by Discord: a breach of the main Discord messaging system, theft of all private messages, password or token theft, full-card exposure, publication of every alleged file, a confirmed 1.5-terabyte or multi-million-image leak, or identity theft affecting every person in the estimate.
Use “accessed” or “potentially exposed” unless a source establishes exfiltration or publication. An attacker’s claim that data was stolen is not proof that all claimed records were taken or made public.
Free tools Windows power users keep installed
One-click scans. No signup required.
Lawsuit and compensation status
A proposed federal class action, Uceta v. Discord, Inc., was filed in the Northern District of California on October 7, 2025. The complaint alleges that Discord and its support provider failed to protect personal information. A consolidated amended complaint later named Discord and 5CA; the docket records a joint case-management statement filed February 27, 2026: court docket.
The complaint’s allegations are not adjudicated facts. The available sources do not establish a final judgment, settlement, certified class or generally available compensation program. Keep official notices and records of expenses or fraud, and obtain individualized legal advice before relying on any deadline or claim theory. Discord’s Terms of Service include arbitration and class-action provisions whose effect can depend on location, the applicable terms, registration date and opt-out history.
Bottom line
This was a serious compromise of Discord-related customer-support data at 5CA, but Discord’s official account does not describe a wholesale breach of Discord’s platform. The practical response is targeted: verify any notice independently, secure the account if there are takeover indicators, monitor payments, and use credit-freeze and identity-fraud precautions when an official notice identifies an exposed government ID.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




