HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTLOCATIONPIIMediumContained
Discord Inc.
bd_c70a5de9bd46eff8 · schema v1 · pii pii-v1
Full breach record for Discord Inc. →Discord Inc. disclosed that a third party obtained unauthorized access to its customer service platform via a compromised vendor device between September 20-22, 2025. The incident was discovered on September 25, 2025. Affected data includes names, contact info, usernames, dates of birth, government ID photos, limited payment info, IP addresses, and support messages. Discord revoked vendor access, engaged forensics, notified law enforcement, and offered 12 months of credit monitoring.
California clockDiscovered Sep 25, 2025 → Notified Oct 3, 20258d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_ded551c03660a631Montana State AGfiled 2025-11-26Verified
- bd_78e85d3aaf14ec30Indiana State AGfiled 2025-11-24(2d gap)Verified
- bd_9f1c7efe99906a6aNew Hampshire State AGfiled 2025-12-01(5d gap)Verified
- bd_a591e2f5f8077ec0Texas State AGfiled 2025-12-05(9d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 33d gap
- bd_83d20831ef0a9cc9Vermont State AGfiled 2025-12-29(33d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614835
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2025
- Raw hash
- d95ac7afb4861092a8c49c7b07147ea9e0b4aa309d23d258b5dd7ab35620c9be
Reporting entity
- Name
- Discord Inc.norm: discord
- Domain
- discord.com
Victim entity
- Name
- Discord Inc.norm: discord
- Domain
- discord.com
Incident
- Discovered
- Sep 25, 2025
- Materiality determined
- —
- Notification sent
- Oct 3, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTLOCATIONPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Third party
- via Customer support provider
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 8d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 25, 2025→ Notified: Oct 3, 20258d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.