Identification Images of Seventy Thousand Members Could Have Been Leaked, According to Discord
Discord, a messaging platform widely used by gaming communities, announces that verified identity pictures of approximately 70,000 users may have been exposed in the wake of a cyber-attack.
Third-Party Service Attacked
The platform, which has over 200 million users worldwide, reports that cybercriminals had compromised a firm that assisted in confirming the age verification of its members but Discord's own systems was not directly affected.
Account holders can upload official pictures to confirm their age on Discord - a communication platform for gaming enthusiasts to chat and distribute materials with fellow users in the video game ecosystem.
Range of Data Exposure
The exposed information could include private data, fragmentary financial data and messages that were shared with Discord's customer service agents.
Entire financial data remained secure, security codes, or communications and user actions outside of interactions with Discord's customer support agents were exposed, the firm stated.
Remedial Steps
Each compromised user have been notified and Discord is collaborating with police agencies to probe the situation, it mentioned additionally.
The service reported it has terminated the customer support provider's permissions for the infrastructure that was targeted in the breach. Discord did not name the partner organization compromised.
Divergent Reports
Some internet observers have asserted that the information leak was bigger than Discord has revealed.
A representative for Discord stated that those claims are incorrect and "represent a scheme to extort payment" from the company.
"We decline to pay those responsible for their unauthorized deeds," the representative further stated.
Importance of Personal Data
Online intruders often pursue personal data, which can obtain significant value on the illegal marketplace for use in fraudulent schemes.
Data such as full names and official ID numbers is particularly prized because, in contrast to payment information, it generally stays constant over time.
Previous Security Steps
Discord has in the past strengthened its age-verification measures in answer to concerns that some servers on the platform were being utilized to circulate inappropriate and harmful content.
- About 70,000 users compromised
- Partner authentication service company breached
- Fragmentary financial information could be compromised
- Help desk messages could have been viewed
- Authorities participating in investigation