Discord Data Breach: Vendor Denies Hacking, Cites Human Error

A recent data security incident has sparked a dispute between the communication platform Discord and its customer service partner, 5CA. While Discord reported a breach of its vendor's systems, leading to the potential exposure of 70,000 government ID photos, 5CA has countered these claims, stating its systems were not compromised and suggesting human error as the likely cause.
Discord Vendor Disputes Hacking Claims, Suggests Human Error in Data Exposure
In a recent development, Discord disclosed a security incident involving one of its third-party customer support providers, 5CA. This incident, which occurred around October 14, 2025, at 4:09 PM UTC, reportedly led to the potential exposure of approximately 70,000 government-issued identification photos. These photos were utilized by the vendor for age-related appeal reviews. Discord emphasized that this was not a direct breach of its own systems but rather of a service provider.
However, 5CA has publicly refuted Discord's characterization of the event, stating clearly on its official website that it was \"not hacked.\" The company asserts that none of its internal systems were compromised and that it does not directly handle government-issued IDs for its clients. 5CA has launched a comprehensive forensic investigation into the matter, collaborating with cybersecurity experts and ethical hackers. Preliminary findings suggest that the incident might stem from \"human error\" occurring outside of 5CA's systems. The company maintains that its data protection measures, including access controls, encryption, and monitoring, remain fully operational and are under heightened review.
Both Discord and 5CA are currently under scrutiny, with requests for clarification on the precise nature of the \"human error\" and the specific entity responsible for holding the exposed government ID photos. This evolving situation highlights the complexities and shared responsibilities in modern data security, particularly when involving third-party vendors.
This incident underscores the critical importance of robust security protocols and clear communication between companies and their vendors regarding data handling. The conflicting narratives from Discord and 5CA emphasize the need for thorough investigations and transparency to rebuild user trust. It also serves as a stark reminder for individuals to be vigilant about the personal information they share online, even with trusted platforms, as data breaches can originate from unexpected sources within the supply chain.