Discord Data Breach: User IDs Exposed in Age Verification Flaw

Discord Data Breach: User IDs Exposed in Age Verification Flaw

A significant data security lapse has affected Discord, the popular communication platform favored by gamers. A third-party vendor responsible for age verification checks experienced a security breach, potentially exposing sensitive information belonging to approximately 70,000 Discord users globally.

The compromised data includes government-issued photo IDs, names, email addresses, contact details, IP addresses, and correspondence with Discord's customer service. While full credit card information and passwords were not accessed, the attacker reportedly attempted to extort the vendor for a ransom.

The breach came to light recently, with the scale of exposed photo IDs emerging shortly after. The UK's Information Commissioner's Office (ICO), the regulatory body for data protection, has received a report from Discord and is currently assessing the details of the incident.

The exposed photos were submitted by users appealing age-related restrictions imposed by Discord. The platform, widely used for text, voice, and video communication, requires age verification in certain cases, particularly due to regulations in countries like the UK that mandate age checks on social media and messaging services under laws like the Online Safety Act. This incident highlights the growing risk of data breaches targeting companies specializing in age verification, as these organizations hold substantial volumes of sensitive personal data.

Discord acknowledged the breach in a statement, confirming that an unauthorized party gained access to information from users who had contacted their customer support and/or trust and safety teams through a third-party vendor. The company clarified that the affected users had submitted government ID photos to verify their age for appeal purposes.

To regain access to the platform after age-related restrictions, users were required to upload an image of their government-issued photo ID along with their Discord username.

Nathan Webb, a cybersecurity consultant at Acumen Cyber, emphasized the severity of the incident. He stressed that companies remain accountable for data security, even when processes like age verification are outsourced. Organizations must recognize that delegating tasks does not absolve them of their responsibility to maintain robust data protection and security standards.

Related articles