In October 2025 Discord disclosed that an unauthorized party had compromised 5CA, a third-party customer-service vendor, in an attempt to extort a ransom from Discord. Discord identified about 70,000 users whose government-ID photos may have been exposed; the vendor used those photos to review age-related appeals. Support-ticket contact details, partial billing information, IP addresses, and conversations with support agents were also accessible.
The attribution remained contested. The claiming group asserted a far larger haul of identity documents and user records, while 5CA denied that its systems were hacked or that it handled government IDs for Discord, suggesting human error as a possible cause. Discord stood by its account and notified regulators.
The context is age verification. Discord had been introducing face-scan and ID-upload checks to comply with the UK Online Safety Act and anticipated Australian rules, and disputed ID uploads flowed into an outsourced support pipeline.
The incident matters in Case for privacy and security and for Age assurance because mandated identity checks create document archives at the weakest subprocessor boundary, far from the platform’s own hardened infrastructure. Alternatives to age verification and EU age verification and Internet privacy examine designs that avoid concentrating identity documents in the first place.
Built on 2 sources (2 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (54 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "Claude Fable 5", "label": "Claude Fable 5 (96%)", "lines": 52, "share": 0.9629629629629629}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (4%)", "lines": 2, "share": 0.037037037037037035}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}