{"id":1437,"date":"2025-10-14T20:09:22","date_gmt":"2025-10-14T16:09:22","guid":{"rendered":"https:\/\/www.actutech.app\/discord-blamed-a-vendor-for-its-data-breach-now-the-vendor-says-it-was-not-hacked\/"},"modified":"2025-10-14T20:09:22","modified_gmt":"2025-10-14T16:09:22","slug":"discord-blamed-a-vendor-for-its-data-breach-now-the-vendor-says-it-was-not-hacked","status":"publish","type":"post","link":"http:\/\/www.actutech.app\/en\/discord-blamed-a-vendor-for-its-data-breach-now-the-vendor-says-it-was-not-hacked\/","title":{"rendered":"Discord blamed a vendor for its data breach \u2014 now the vendor says it was \u2018not hacked\u2019"},"content":{"rendered":"<figure>\n<p><img decoding=\"async\" alt=\"\" data-caption=\"\" data-portal-copyright=\"\" data-has-syndication-rights=\"1\" src=\"https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/acastro_STK062_03.jpg?quality=90&amp;strip=all&amp;crop=0,0,100,100\" \/><figcaption>\n\t\t<\/figcaption><\/p><\/figure>\n<p class=\"has-text-align-none\">5CA is a customer service support company that works with Discord. Recently, the chat platform <a href=\"https:\/\/www.theverge.com\/news\/798084\/an-update-from-discord-on-its-customer-service-data-breach\" target=\"_blank\" rel=\"noopener\">said the vendor had been breached<\/a> as part of a \u201csecurity incident\u201d where 70,000 government ID photos may have leaked. Now, 5CA says <a href=\"https:\/\/5ca.com\/blog\/holding-statement-security-incident\/\" target=\"_blank\" rel=\"noopener\">in a post on its website<\/a> that it was \u201cnot hacked.\u201d<\/p>\n<p class=\"has-text-align-none\"><a href=\"https:\/\/discord.com\/press-releases\/update-on-security-incident-involving-third-party-customer-service\" target=\"_blank\" rel=\"noopener\">According to Discord<\/a>, \u201cthis incident impacted a limited number of users who had communicated with our Customer Support or Trust &amp; Safety teams,\u201d and \u201cof the accounts impacted globally, we have identified approximately 70,000 users that may have had government-ID photos exposed, which our vendor used to review age-related appeals.\u201d The company said that (emphasis Discord\u2019s) \u201cthis was <em>not<\/em> a breach of Discord, but rather a breach of a third party service provider, 5CA, that we used to support our customer service efforts.\u201d<\/p>\n<p class=\"has-text-align-none\">However, on its website, 5CA shared its own statement, which I am including in full below (with emphasis 5CA\u2019s):<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-text-align-none\">We are aware of media reports naming <strong>5CA<\/strong> as the cause of a data breach involving one of our clients. Contrary to these reports, we can confirm that none of <strong>5CA\u2019s systems<\/strong> were involved, and 5CA has not handled any government-issued IDs for this client. All our platforms and systems remain secure, and client data continues to be protected under strict data protection and security controls.<\/p>\n<p class=\"has-text-align-none\">We are conducting an ongoing forensic investigation into the matter and collaborating closely with our client, as well as external advisors, including cybersecurity experts and ethical hackers. Based on interim findings, we can confirm that the incident occurred <strong>outside of our systems<\/strong> and that <strong>5CA was not hacked<\/strong>. There is no evidence of any impact on other 5CA clients, systems, or data. Access controls, encryption, and monitoring systems are fully operational and, as a precautionary measure, are under heightened review.<\/p>\n<p class=\"has-text-align-none\">Our preliminary information suggests the incident may have resulted from <strong>human error<\/strong>, the extent of which is still under investigation. We remain in close contact with all relevant parties and will share verified findings once confirmed.<\/p>\n<\/blockquote>\n<p class=\"has-text-align-none\">We\u2019ve asked 5CA to confirm if it handled government ID photos and if it could share more information about the \u201chuman error\u201d that may have been involved. We\u2019ve also asked Discord if it can confirm which company was in possession of the photos of government IDs that may have been accessed.<\/p>","protected":false},"excerpt":{"rendered":"<p>5CA is a customer service support company that works with Discord. Recently, the chat platform said the vendor had been [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1437","post","type-post","status-publish","format-standard","hentry","category-non-classe"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/posts\/1437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/comments?post=1437"}],"version-history":[{"count":0,"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/posts\/1437\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/media?parent=1437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/categories?post=1437"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/tags?post=1437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}