Discord has named 5CA, a third-party service provider, as the vendor responsible for the data breach that exposed the information and ID photos of over 70,000 users worldwide.
However, 5CA denies any wrongdoing, stating that its systems haven’t been hacked.
On October 3, 2025, Discord announced that an unauthorized party gained access to one of its third-party customer service providers, affecting users who had interacted with Customer Support or Trust & Safety.
In an updated statement on October 9, Discord formally stated that 5CA, a Netherlands-based customer experience firm, was the provider involved in the data breach.
The attackers, who identified themselves as the Scattered Lapsus$ Hunters (SLH), allegedly breached 5CA’s support ticket environment and took 1.6 terabytes of data.
The attackers identified themselves as the Scattered Lapsus$ Hunters (SLH).
Author's summary: Discord names 5CA as responsible for data breach.