the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Discord Vendor 5CA Denies Breach Claim in 70K ID Photo Leak

ArticlesNewsletters
ArticlesNewsletters
cybersecurity/vendor management

Discord Vendor 5CA Denies Breach Claim in 70K ID Photo Leak

5CA disputes Discord's claim it was breached in security incident affecting 70,000 IDs

by The Tech Buzz

PUBLISHED: Tue, Oct 14, 2025, 4:44 PM UTC | UPDATED: Sun, Apr 26, 2026, 1:26 PM UTC

Add as a preferred source on Google
Discord Vendor 5CA Denies Breach Claim in 70K ID Photo Leak

A messy blame game is unfolding over whose systems actually failed in Discord's massive data breach. The chat platform initially pointed fingers at vendor 5CA for a breach exposing 70,000 government ID photos. Now 5CA is firing back, claiming it was never hacked and suggesting "human error" may be to blame instead.

The finger-pointing started fast when Discord announced last week that 70,000 government ID photos had potentially been exposed in what it called a vendor breach. The company was quick to clarify this wasn't a Discord problem - it was their third-party customer service provider 5CA that got hacked.

But 5CA isn't taking the blame lying down. In a statement posted to its website, the customer service vendor categorically denies being breached at all. "We can confirm that none of 5CA's systems were involved, and 5CA has not handled any government-issued IDs for this client," the company states.

That's a pretty damning contradiction to Discord's version of events. According to Discord's official press release, the incident "impacted a limited number of users who had communicated with our Customer Support or Trust & Safety teams." The company specifically said government ID photos were exposed that "our vendor used to review age-related appeals."

So either Discord is wrong about which vendor handled the IDs, or 5CA is being less than truthful about its role in the process. The stakes here are huge - we're talking about 70,000 people's sensitive government identification documents potentially floating around in the wrong hands.

Advertisement

5CA's defense gets more interesting when you dig into their explanation. The company admits an incident occurred but says it happened "outside of our systems." Their preliminary investigation suggests "human error" might be the culprit, though they won't elaborate on what kind of error or who made it.

This human error angle raises some uncomfortable questions. If 5CA didn't handle the IDs and wasn't breached, then where exactly were these photos stored? And if human error is to blame, whose human made the error? Discord's? Another vendor's? Someone at 5CA despite their denials?

The cybersecurity implications here go beyond just this one incident. Enterprise companies often rely on complex webs of third-party vendors for customer service, data processing, and security functions. When something goes wrong, figuring out exactly where the failure occurred can be like untangling a ball of yarn.

5CA says it's working with "cybersecurity experts and ethical hackers" to get to the bottom of what happened. They've also put their systems under "heightened review" as a precautionary measure, even though they maintain nothing was compromised on their end.

Advertisement

Meanwhile, Discord users who uploaded government IDs for age verification are left wondering exactly how secure their data really is. The company has been relatively quiet about additional details since the initial disclosure, referring questions back to their original statement.

This kind of vendor blame game isn't uncommon in major data breaches. Companies naturally want to limit their liability and protect their reputation by pointing to third-party failures. But when the vendor pushes back this hard, it usually means there's more to the story.

The forensic investigations from both companies should eventually reveal what actually happened. Until then, affected users are stuck in the middle of a corporate he-said-she-said while their sensitive documents remain potentially exposed. It's exactly the kind of scenario that makes people think twice before uploading their driver's license to verify their account.

This Discord-5CA dispute highlights a growing problem in enterprise security: when breaches happen across complex vendor networks, figuring out who's actually responsible becomes a blame game while users' data hangs in the balance. Both companies are conducting investigations, but 70,000 people's government IDs are still potentially compromised while the corporate finger-pointing continues. The real test will be what the forensic investigations reveal - and whether the affected users ever get clear answers about how their sensitive documents ended up exposed.

More Topics:
vendor managementgovernment ID

Advertisement

Advertisement

Trending Now

1

Nscale Eyes $3.5B Pre-IPO Round After Anthropic Deal

2

GoPro CEO Vows Cameras Stay Core After Starman Deal

3

Judge Splits Ruling in X vs. Twitter Rival Fight

4

Tim Cook Steps Down, Ternus Takes Apple's Helm

5

Google's Lyria 3.5 Brings AI Music to Gemini

People Also Ask

Discord reported that 70,000 government ID photos were potentially exposed in what it called a vendor breach at third-party customer service provider 5CA. However, 5CA denies being breached and claims it never handled government IDs for Discord.

5CA categorically denies being breached, stating "none of 5CA's systems were involved" and that it "has not handled any government-issued IDs for this client." The company suggests human error outside their systems may be responsible.

70,000 Discord users who uploaded government ID photos for age verification were potentially affected. These users had communicated with Discord's Customer Support or Trust & Safety teams and submitted IDs for age-related appeals.

Government-issued ID photos were potentially exposed in the breach. These sensitive documents were uploaded by users for age verification purposes when appealing to Discord's Customer Support or Trust & Safety teams.

There's a major dispute between the companies. Discord claims 5CA was breached and handled the ID photos, while 5CA flatly denies being hacked or handling any government IDs for Discord, creating contradictory accounts of the incident.

Both Discord and 5CA are conducting separate forensic investigations. 5CA is working with cybersecurity experts and ethical hackers while putting their systems under heightened review to determine what actually happened.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23