<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Discord suffers data breach &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/discord-suffers-data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Mon, 13 Oct 2025 11:10:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>Discord suffers data breach &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Discord suffered data breach due to vendor attack: ESET analyzes it and comments</title>
		<link>https://bitfinance.news/en/discord-suffered-data-breach-due-to-vendor-attack-eset-analyzes-it-and-comments/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 13 Oct 2025 13:00:44 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[attention and care with vendors]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data that was affected and/or compromised]]></category>
		<category><![CDATA[Discord messaging platform]]></category>
		<category><![CDATA[Discord suffers data breach]]></category>
		<category><![CDATA[ESET analyzes and comments]]></category>
		<category><![CDATA[ESET Global Security Advisor]]></category>
		<category><![CDATA[ESET Venezuela]]></category>
		<category><![CDATA[Head of ESET Latin America Research Lab]]></category>
		<category><![CDATA[Jake Moore]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[strengthening the supply chain]]></category>
		<category><![CDATA[vendor attack]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=116631</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="667" src="https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Los servicios de terceros y sus debilidades, explica Jake Moore, Global Security Advisor de ESET, “son más difíciles de monitorear y controlar, y a menudo guardan información sensible, por lo que se están transformando en objetivos comunes para los cibercriminales”  " decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R.jpg 1000w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R-768x512.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p>The Discord messaging platform, used by more than 200 million people each month, confirmed last Friday that it was affected by a security incident in its customer support service, managed by a third party. The third-party provider suffered an extortion attack, similar to ransomware, in which attackers accessed sensitive data and demanded a ransom to [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/discord-suffered-data-breach-due-to-vendor-attack-eset-analyzes-it-and-comments/">Discord suffered data breach due to vendor attack: ESET analyzes it and comments</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="667" src="https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Los servicios de terceros y sus debilidades, explica Jake Moore, Global Security Advisor de ESET, “son más difíciles de monitorear y controlar, y a menudo guardan información sensible, por lo que se están transformando en objetivos comunes para los cibercriminales”  " decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R.jpg 1000w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-Discord-sufre-filtracion-de-datos-por-ataque-a-proveedor-Suministrada-por-ESET-y-Comstat-R-768x512.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p style="text-align: justify;">The Discord messaging platform, used by more than <strong><a href="https://discord.com/company#:~:text=In%20Numbers-,200M%2B,Source%3A%20%E2%93%98,-1.9B" target="_blank" rel="noopener">200 million people each month</a>, </strong>confirmed last Friday that it was affected by a security incident in its customer support service, managed by a third party. The third-party provider suffered an extortion attack, similar to ransomware, in which attackers accessed sensitive data and demanded a ransom to retain the stolen information.  <a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a>, a leading company in proactive threat detection, is analyzing the incident, which affected users who had interacted with customer service and trusted and safety representatives.</p>
<p style="text-align: justify;">Among the leaked and compromised data were identity documents, partial credit card details, and payment history.</p>
<p style="text-align: justify;">According to <strong>the incident notification that <a href="https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service" target="_blank" rel="noopener">Discord sent to affected users</a></strong> and made public on its website, the <strong>attackers did not access the most sensitive information</strong>, such as physical addresses, full credit or debit card details, or authentication data. &#8220;Nor did they access messages other than those exchanged with the customer support center,&#8221; they detailed.</p>
<figure id="attachment_116627" aria-describedby="caption-attachment-116627" style="width: 794px" class="wp-caption alignnone"><img decoding="async" class="wp-image-116627 size-full" src="https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-2-Acompanamiento-del-texto.jpg" alt="Official statement on Discord's website (Source: Discord)" width="794" height="510" srcset="https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-2-Acompanamiento-del-texto.jpg 794w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-2-Acompanamiento-del-texto-300x193.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-2-Acompanamiento-del-texto-768x493.jpg 768w, https://bitfinance.news/wp-content/uploads/2025/10/Imagen-referencial-2-Acompanamiento-del-texto-210x136.jpg 210w" sizes="(max-width: 794px) 100vw, 794px" /><figcaption id="caption-attachment-116627" class="wp-caption-text">Official statement on Discord&#8217;s website (Source: Discord)</figcaption></figure>
<p style="text-align: justify;">While it is asserted that the cybercriminal group did not have direct access to the platform&#8217;s servers, ESET maintains that <strong>the case demonstrates how a service with high security standards can be weakened at one of the links in its supply chain.</strong></p>
<p style="text-align: justify;">Third-party services and their weaknesses, explains Jake Moore, ESET Global Security Advisor, &#8220;are more difficult to monitor and control, and they often store sensitive information, so they are becoming common targets for cybercriminals.&#8221;</p>
<p style="text-align: justify;">A security incident reportedly occurred on September 20, which is still under investigation. Since October 3, the platform began notifying each affected party about the breach and has issued a statement alerting the community at large.</p>
<h2 style="text-align: justify;"><strong>Data affected and/or compromised</strong></h2>
<p style="text-align: justify;">According to the information published by Discord, the compromised data includes:</p>
<ul style="text-align: justify;">
<li>Usernames, email addresses, and contact information.</li>
<li>Payment information, such as the last four digits of card details and purchase history.</li>
<li>IP addresses.</li>
<li>Messages and attachments sent to customer service, or inquiries to members of the platform&#8217;s trust and safety department.</li>
<li>Corporate information, such as training materials and internal presentations.</li>
</ul>
<p style="text-align: justify;">According to the same alert, the data accessed by cybercriminals includes &#8220;a small number&#8221; of identity documents, such as driver&#8217;s licenses or passports, which are often requested to verify a Discord member&#8217;s age. While the volume of these leaked documents is not detailed, the platform assures that the incident notification email specifies this information for each affected user. This means that if you receive an email notifying you of the data breach, it will clarify which data was compromised.</p>
<p style="text-align: justify;"><em>“The recommendation for any user of the platform who has been affected, or who uses Discord, is <strong>to pay special attention to any communication that appears to originate from Discord, as the possibility of data being used in targeted phishing campaigns is higher.</strong> Cybercriminals may not only leverage the leaked information, but also the news of the leak to use that excuse or bait to launch a specific campaign targeting users of the platform—even if they were not the targets of this latest leak,”</em> warns <strong>Camilo Gutiérrez Amaya, Head of the ESET Latin America Research Lab.</strong></p>
<p style="text-align: justify;">Regardless of whether you were notified or not, ESET assures that this is a good opportunity to review some recommendations that may be essential in the event of incidents like this:</p>
<ul style="text-align: justify;">
<li>Check if you have two-step verification enabled on your account. This provides an additional layer of protection against login credentials leaks.</li>
<li>Review payment transactions if you use Discord Nitro or other paid services.</li>
</ul>
<h3 style="text-align: left;"><strong>Importance of strengthening the supply chain (be careful with suppliers)</strong></h3>
<p style="text-align: justify;">At the time of this publication, and according to an article on the specialized website <a href="https://www.bleepingcomputer.com/news/security/discord-discloses-data-breach-after-hackers-steal-support-tickets/#:~:text=update%3A%20while%20slh%20initially%20appeared%20to%20confirm%20to%20bleepingcomputer%20that%20they%20were%20behind%20the%20discord%20zendesk%20compromise%2C%20they%20later%20stated%20that%20it%20was%20a%20different%20group%20that%20they%20know%20and%20interact%20with." target="_blank" rel="noopener">BleepingComputer</a>, the Scattered Lapsus$ Hunters (SLH) ransomware group had initially claimed responsibility for the attack, although they later told that outlet that the attack was carried out by another group with ties to SLH.</p>
<p style="text-align: justify;">“These types of incidents at third-party suppliers are a reminder of the importance of strengthening the <a href="https://www.welivesecurity.com/es/seguridad-corporativa/como-mitigar-riesgo-cadena-suministro/" target="_blank" rel="noopener">supply chain</a>. A robust cybersecurity policy must include and address all the links that make up the supplier network. It is also key for users to understand the importance of <a href="https://www.welivesecurity.com/es/privacidad/filtraciones-contrasenas-como-comprobar-afectado/" target="_blank" rel="noopener">staying informed and alert</a> to incidents that could compromise the security and privacy of their data, and to remember the basic measures they can take to address them, or at least be better prepared for these types of situations, which are becoming <a href="https://www.weforum.org/stories/2025/08/to-end-the-data-breach-epidemic-do-we-need-to-rethink-data-sharing/#:~:text=exposing%20raw%20data.-,Data%20breaches%20are%20rising,organization%20that%20collected%20it.,-These%20breaches%20go" target="_blank" rel="noopener">more frequent</a>,” concludes Gutiérrez Amaya of ESET.</p>
<p style="text-align: justify;">ESET invites you to learn more about cybersecurity by visiting: <a href="https://www.welivesecurity.com/es/" target="_blank" rel="noopener">https://www.welivesecurity.com/es/</a>.</p>
<p style="text-align: justify;">For other useful preventive information, it is also available in Venezuela: <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a>, and its social media channels @eset_ve. Also available on Instagram (<a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>) and Facebook (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p><em>With information and reference images provided by ESET and Comstat Rowland</em></p>
<p><em>Visit our news channel on </em><a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener"><em><strong>Google News</strong></em></a><em> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on </em><a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><em><strong>X/Twitter</strong></em></a><em> and </em><a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><em><strong>Instagram</strong></em></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/discord-suffered-data-breach-due-to-vendor-attack-eset-analyzes-it-and-comments/">Discord suffered data breach due to vendor attack: ESET analyzes it and comments</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
