Discord hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Discord confirmed a third-party customer service system compromise that gave an unauthorized party limited access to support infrastructure used by the company. The incident affected Discord's customer support and Trust and Safety environment and prompted isolation, investigation, and remediation. It matters because the access touched a core service workflow and was tied to an extortion demand.
Related Happenings
Mongolian governmental institution hit by network compromise
Incident
First: 23.04.2026 12:04
Last: 23.04.2026 12:04
Sources 1
About this happening:
A **Mongolian governmental institution** was found to have **about 12 systems** infected by **GopherWhisper** backdoors, exposing a live government compromise and the potential fo...
Mongolian governmental institution hit by network compromise
IncidentAbout this happening: A **Mongolian governmental institution** was found to have **about 12 systems** infected by **GopherWhisper** backdoors, exposing a live government compromise and the potential fo...
W3LL Microsoft 365 adversary-in-the-middle phishing campaign
Campaign
First: 13.04.2026 21:55
Last: 13.04.2026 21:55
Sources 1
About this happening:
The **W3LL** phishing operation turned into a high-volume **Microsoft 365** credential-theft campaign, exposing **more than 17,000 victims worldwide** to **BEC** risk. The kit use...
W3LL Microsoft 365 adversary-in-the-middle phishing campaign
CampaignAbout this happening: The **W3LL** phishing operation turned into a high-volume **Microsoft 365** credential-theft campaign, exposing **more than 17,000 victims worldwide** to **BEC** risk. The kit use...
UNC6783 BPO compromise campaign targeting downstream companies
Campaign
First: 09.04.2026 00:46
Last: 09.04.2026 00:46
Sources 1
About this happening:
**UNC6783** is an active **BPO compromise campaign** targeting **business process outsourcers** and large enterprises to reach downstream environments for **extortion**. The opera...
UNC6783 BPO compromise campaign targeting downstream companies
CampaignAbout this happening: **UNC6783** is an active **BPO compromise campaign** targeting **business process outsourcers** and large enterprises to reach downstream environments for **extortion**. The opera...
ShinyHunters widespread Okta SSO data theft campaign
Campaign
First: 03.04.2026 20:41
Last: 03.04.2026 20:41
Sources 1
About this happening:
**ShinyHunters** is tied to a **widespread campaign** that compromised **Okta SSO accounts** to steal data from third-party **cloud storage** and **SaaS platforms**, widening the...
ShinyHunters widespread Okta SSO data theft campaign
CampaignAbout this happening: **ShinyHunters** is tied to a **widespread campaign** that compromised **Okta SSO accounts** to steal data from third-party **cloud storage** and **SaaS platforms**, widening the...
2025 Rise in legitimate-access intrusions across enterprise sectors
Target Trend
First: 01.04.2026 17:05
Last: 01.04.2026 17:05
Sources 1
About this happening:
**Legitimate access abuse** is now a leading intrusion pattern across **2025** investigations, increasing the risk of stealthy compromise across **manufacturing, healthcare, MSPs,...
2025 Rise in legitimate-access intrusions across enterprise sectors
Target TrendAbout this happening: **Legitimate access abuse** is now a leading intrusion pattern across **2025** investigations, increasing the risk of stealthy compromise across **manufacturing, healthcare, MSPs,...
Timeline
-
04.10.2025 14:16 1 articles · 7mo ago
Discord customer support compromise and data theft
Victim Impact UpdateOn 2025-09-20, an unauthorized party gained limited access to a third-party customer service system used by Discord and stole partial payment information and personally identifying data associated with a limited number of Discord users who had interacted with customer support and Trust and Safety teams.
Show sources
- Hackers steal identifiable Discord user data in third-party breach — www.bleepingcomputer.com — 04.10.2025 14:16
-
04.10.2025 14:16 4 articles · 7mo ago
Discord public disclosure and remediation response
Initial DisclosureOn 2025-10-04, Discord publicly disclosed the compromise and said it revoked the customer support provider’s access to its ticketing system, launched an internal investigation, engaged a leading computer forensics firm to support investigation and remediation efforts, and engaged law enforcement after the attackers demanded a ransom for not leaking the stolen information.
Show sources
- Hackers steal identifiable Discord user data in third-party breach — www.bleepingcomputer.com — 04.10.2025 14:16
- Discord discloses data breach after hackers steal support tickets — www.bleepingcomputer.com — 04.10.2025 14:16
- Discord Reveals Data Breach Following Third-Party Compromise — www.infosecurity-magazine.com — 07.10.2025 13:30
- Hackers claim Discord breach exposed data of 5.5 million users — www.bleepingcomputer.com — 09.10.2025 03:22