Breach / exposure. Updated 2026-09-13. About 6 minutes to read.
Treat any call, DM or unfamiliar email about the breach as a scam, add a passkey or authenticator app to Discord, and replace any ID document Discord told you was exposed.
Discord's most serious recent breach did not happen inside Discord's own servers. In October 2025 the company said an attacker had compromised 5CA, an outside firm that handled its customer support tickets, and that about 70,000 users worldwide may have had photos of government ID exposed. Discord said passwords and normal Discord messages were not part of it.
If you ever opened a support ticket or appealed an age decision, assume your name, email address, IP address and anything you sent to support is now in criminal hands. This guide explains what that data lets scammers do, what to lock down today, and what to do if a photo of your ID was in the set.
Discord disclosed the incident on 3 October 2025 and named 5CA in an update on 9 October. It said the attacker reached a third-party ticketing system, and that only people who had contacted its Customer Support or Trust and Safety teams were affected. 5CA publicly disputed parts of that account, so the two companies do not agree on where the failure happened. For you, the outcome is the same.
This was not the first vendor incident. In 2023 Discord warned users that a support agent's account at an outside provider had been accessed, exposing ticket contents and attachments for a much smaller group.
Support tickets are useful to scammers because they contain real details that make a fake message believable. A crook who can quote your old ticket number, your username and the last four digits of your card sounds exactly like Discord staff.
An ID photo is worse. It shows your full name, date of birth, address, document number and face. Criminals use ID images to pass identity checks at crypto exchanges and online lenders, to open phone accounts, and to convince a mobile carrier to move your number to their SIM.
Discord said it contacts affected users only by email from noreply@discord.com and will not phone anyone about this incident. A caller, a DM or a text claiming to be Discord staff is a scam.
Check your inbox and spam folder for an October 2025 email from noreply@discord.com. Do not click links in it. If you were told your ID was included, act on the document itself, not just your Discord account.
Age checks are spreading. In February 2026 Discord announced teen-by-default settings worldwide, with a face scan or an ID upload for anyone who needs to prove they are an adult, then delayed the global rollout after a backlash. Laws in the UK and Australia are pushing platforms in the same direction.
If you are asked, pick the method that shares the least. Discord says face scans happen on your device and ID images are deleted once your age is confirmed. The 5CA breach shows that deletion promises depend on every vendor in the chain keeping them, so avoid sending ID over a support ticket unless there is no other way.
Discord says no passwords or authentication data were exposed. Change it anyway if you reuse it anywhere, because scammers will use the breach as an excuse to phish for it.
Discord emailed affected users from noreply@discord.com. If you never contacted Discord support or Trust and Safety, you were very unlikely to be included. If you did, assume your ticket contents were exposed even without an email.
Deleting it does not recall data already stolen from the vendor. It does reduce future exposure. If you keep the account, secure it with a passkey and remove old support attachments from your own records.
Complain to Discord first. In the UK you can then go to the ICO. In Australia the OAIC generally expects you to give the company 30 days to respond before you complain. In the US, report misuse at IdentityTheft.gov.
Yes, with a passkey or authenticator app, no reused password and direct messages from strangers turned off. The realistic risk now is phishing that uses your leaked details, not someone logging in with a stolen password.