
Discord is being blackmailed (Photo: Discord).
Popular communication platform Discord has officially confirmed a serious security incident that affected the data of a certain number of users.
According to Discord, the incident occurred due to a third-party provider being hacked, not Discord's main system.
However, the incident raises big questions about supply chain safety of major platforms.
According to the announcement, an unauthorized attacker successfully penetrated the provider's system and accessed data of users who had contacted Discord's Customer Support or Trust & Safety department. The purpose of the attack is believed to be to extort money from Discord.
Discord said the incident only affected a "limited number of users." However, the exposed information included a lot of sensitive data. Specifically, the data that was accessed without authorization includes:
Personal Information: Name, Discord username, email address, and other contact information.
Limited payment data: Payment type, last four digits of credit card, and purchase history.
Technical information: User's IP address.
Content of the conversation: Message history between the user and the customer service agent.
More seriously, Discord determined that approximately 70,000 users globally may have had their government ID photos exposed. These are images that users provide to Discord partners for the purpose of verifying age-related appeals.
Discord also reassured users that critical information like full credit card numbers, CCV codes, passwords, and authentication data remains safe.
The incident also did not affect users' private messages or activity on the platform, beyond what they communicated with support.
Discord's Response
Immediately after discovering the incident, Discord took drastic action to prevent and investigate by immediately revoking this service provider's access to the request processing system.
The company has also launched an internal investigation and hired a leading computer forensics firm to assist with analysis and remediation.
The Discord incident has once again sounded the alarm about "supply chain risks" in the tech industry.
Even if internal systems are well secured, vulnerabilities from external partners can still cause serious damage to data and reputation.
The platform advises all users, especially those affected, to be extra vigilant of suspicious messages, emails or calls in the coming period. Malicious actors may take advantage of the leaked information to carry out phishing attacks.
Compiled from The Verge, Discord
Source: https://dantri.com.vn/cong-nghe/ung-dung-discord-bi-tong-tien-nhieu-nguoi-dung-lo-thong-tin-nhay-cam-20251009170003107.htm
Comment (0)