AJC Strengthens Cyber Resilience in Mutuals
Mutual organisations continue to play a pivotal role in the UK financial landscape, and the need for robust cyber security...
Read MoreAs one of the world’s largest online communication platforms, Discord hosts millions of users across diverse communities – from gaming and education to professional collaboration. Its architecture depends on a network of third-party service providers that support moderation, customer service, and verification processes. That structure, whilst efficient, has now come under scrutiny following a significant data breach involving one such vendor.
In early October 2025, Discord disclosed a security incident involving a third-party customer support vendor. Although Discord insists its own infrastructure was not directly compromised, the attacker accessed user data held in support systems.
Discord estimates that approximately 70,000 users may have had their government-issued ID (e.g. passports, driving licences) accessed – these were submitted during appeals related to age-verification determinations. Personal data including names, usernames, email addresses, conversation transcripts with support agents, and billing metadata (e.g. payment type and last four digits of a credit card) may also have been exposed.
According to Discord, full credit card numbers, CVV codes, passwords, and private user messages were not included in the breach. The company claims it acted swiftly by revoking vendor access to its ticketing system, retaining forensic specialists, engaging law enforcement, and notifying affected individuals via email. It also reported the incident to the relevant data protection authorities.
The implicated vendor, 5CA, has disputed aspects of Discord’s account. 5CA asserts that none of its infrastructure was compromised and that it does not handle government ID documents on Discord’s behalf. The attacker, meanwhile, has claimed to possess millions of stolen images – far exceeding Discord’s estimate of 70,000 affected users. Discord has rejected that claim, describing it as an extortion attempt.
This breach comes amid heightened scrutiny of age-verification requirements. In the UK, the recently implemented Online Safety Act compels social platforms to verify users’ ages for certain types of content. Discord, among others, has relied on ID submissions to meet those obligations.
The use of external contractors to process and store such sensitive information raises pressing questions about accountability and data protection by design. The UK Information Commissioner’s Office (ICO) is reportedly reviewing the case, and analysts note that this incident reinforces a long-standing truth: third parties are often the weakest link in the security chain.
For individuals potentially affected, risks include identity theft and phishing attempts. Organisations handling sensitive identity data should review their third-party contracts, ensure encryption of all stored documents, restrict access through zero-trust principles, and regularly test incident response procedures.
Discord now faces both reputational and legal fallout, including reports of class-action litigation. More broadly, the incident adds weight to an ongoing debate: whether mandatory ID verification can ever fully align with strong privacy standards.
Third-party risk management requires more than supplier questionnaires. AJC works with financial institutions, technology platforms, and regulated firms to identify where vendor relationships create potential exposure, and to build proportionate controls that protect data, reputation, and compliance.
Our support includes:
To discuss how AJC can strengthen your third-party assurance framework, please get in touch with our team.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://www.theverge.com/news/792032/discord-customer-service-data-breach-hack
https://www.theverge.com/news/797051/discord-government-ids-leaked-data-breach
https://www.theguardian.com/media/2025/oct/09/hack-age-verification-firm-discord-users-id-photos
https://www.sfgate.com/tech/article/discord-hit-3-straight-lawsuits-21095310.php
https://www.theverge.com/news/799274/discord-security-breach-5ca-vendor-blamed-not-hacked
https://proton.me/blog/discord-age-verfication-breach
Image accreditation: Yuki Uchida (September 2024) on Wikimedia Commons. Available at: https://commons.wikimedia.org/wiki/File:Tokyo-Game-Show-2024-Day4—2024-09-29_044.jpg
Mutual organisations continue to play a pivotal role in the UK financial landscape, and the need for robust cyber security...
Read MoreThe latest figures from UK Finance paint a troubling picture of the nation’s fraud landscape. In just the first six...
Read MoreThe Financial Conduct Authority (FCA) has criticised UK banks and payment firms for repeatedly missing key opportunities to prevent romance...
Read More