the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Discord's Zendesk breach exposes 70K government IDs amid extortion

ArticlesNewsletters
ArticlesNewsletters
cybersecurity/government IDs

Discord's Zendesk breach exposes 70K government IDs amid extortion

Breaking: Discord confirms 70,000 users had government IDs exposed in third-party breach

by The Tech Buzz

PUBLISHED: Wed, Oct 8, 2025, 10:39 PM UTC | UPDATED: Fri, Sep 4, 2026, 2:58 PM UTC

Add as a preferred source on Google
Discord's Zendesk breach exposes 70K government IDs amid extortion

Discord just confirmed that roughly 70,000 users had their government ID photos exposed through a breach at its third-party customer service provider. The gaming platform is pushing back against extortion attempts while law enforcement investigates the incident that compromised sensitive identity verification documents used for age-related appeals.

Discord is dealing with fallout from a significant data breach that exposed government identification documents for approximately 70,000 users - and the company isn't backing down from extortion demands. The gaming platform confirmed to The Verge that hackers gained access to sensitive ID photos through a compromised third-party customer service system, sparking a high-stakes standoff between the platform and cybercriminals.

The breach centers on Discord's Zendesk instance, which the company uses to handle customer support operations. Security researchers at vx-underground first flagged the incident on social media, revealing that hackers were attempting to extort Discord with claims of possessing "1.5TB of age verification related photos" totaling over 2.18 million images. But Discord spokesperson Nu Wexler pushed back hard against these inflated numbers.

"The numbers being shared are incorrect and part of an attempt to extort a payment from Discord," Wexler told The Verge in a statement. "We will not reward those responsible for their illegal actions." The company's firm stance reflects a growing trend among tech firms to resist ransomware and extortion attempts, even when facing potential reputational damage.

The exposed government IDs were specifically used for age-related appeals, part of Discord's system for verifying users who claim they're old enough to use the platform despite being flagged by age verification systems. This creates a particularly sensitive data exposure, as government-issued identification documents contain the exact personal information that identity thieves prize most.

Advertisement

The timing couldn't be worse for Discord, which has been working to clean up its reputation around child safety and age verification. The platform has faced ongoing scrutiny from lawmakers and parents about underage users accessing inappropriate content. Having the very system designed to protect minors become a vector for data exposure adds insult to injury.

Beyond the ID photos, last week's initial disclosure revealed that hackers also accessed a broader range of user data including full names, usernames, email addresses, the last four digits of credit cards, and IP addresses. This creates a comprehensive profile that could enable sophisticated social engineering attacks against affected users.

Discord moved quickly to contain the damage once the breach was discovered. The company says it has "secured the affected systems and ended work with the compromised vendor" - a decisive break that suggests Discord views the third-party security failure as unacceptable. All 70,000 affected users have been directly contacted about the exposure.

Advertisement

The incident highlights the persistent challenge of third-party vendor security in an era where most tech companies rely heavily on external services. Even companies with strong internal security can find themselves exposed through partners and vendors who may not maintain the same standards. Discord's case serves as a reminder that customer service platforms, which often handle the most sensitive user interactions and data, represent high-value targets for cybercriminals.

Law enforcement agencies and data protection authorities are now involved in the investigation, according to Discord's statement. The company is also working with external security experts to assess the full scope of the breach and strengthen its vendor oversight processes.

For Discord's massive user base - the platform claims over 150 million monthly active users - this breach represents a concerning escalation of the privacy risks that come with age verification requirements. As platforms face increasing pressure to verify user ages, incidents like this raise questions about whether the cure might be worse than the disease.

Discord's firm refusal to pay extortion demands sets an important precedent, but the exposure of 70,000 government IDs through a third-party vendor breach underscores the complex security challenges facing platforms that rely on age verification. As lawmakers push for stricter age verification requirements across social platforms, incidents like this highlight the privacy risks that come with storing sensitive identity documents. The outcome of this investigation could influence how other platforms approach vendor security and whether the tech industry's growing resistance to ransomware payments can hold when user safety is on the line.

More Topics:
government IDsthird-party security

Advertisement

Advertisement

Trending Now

1

Does Gemini Have a Limit? How Google's Usage Caps Actually Work in 2026

2

Black Friday 2026: When It Is, and Why It Often Isn't the Cheapest Day

3

Nscale Eyes $3.5B Pre-IPO Round After Anthropic Deal

4

GoPro CEO Vows Cameras Stay Core After Starman Deal

5

Judge Splits Ruling in X vs. Twitter Rival Fight

People Also Ask

Discord's third-party customer service provider Zendesk was breached, exposing government ID photos of approximately 70,000 users. The breach also compromised names, emails, credit card digits, and IP addresses used for age verification appeals.

Approximately 70,000 Discord users had their government identification documents exposed in the breach. Hackers claimed to have 2.18 million photos totaling 1.5TB, but Discord disputes these inflated numbers as extortion tactics.

The breach exposed government ID photos used for age verification, plus full names, usernames, email addresses, last four digits of credit cards, and IP addresses. This creates comprehensive profiles for potential identity theft.

No, Discord is refusing to pay the extortion demands. Spokesperson Nu Wexler stated 'We will not reward those responsible for their illegal actions,' reflecting the company's firm stance against ransomware payments.

Discord secured affected systems, terminated the relationship with the compromised vendor, contacted all 70,000 affected users directly, and involved law enforcement. The company is working with external security experts to assess the full scope.

Government IDs were used for age-related appeals, where users submit identification to prove they're old enough to use Discord after being flagged by automated age verification systems. This helps verify legitimate adult users.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23