Desk live·
ForensicPost
Cloud/Third party/File 23-0512c

Discord Says a Support Vendor’s Agent Account Exposed Ticket Contents

The compromised account did not belong to Discord. It belonged to an agent at the outsourced customer service provider, and what it held was the queue — email addresses, the messages people had written to support, and whatever they had attached.

Constructed geometry · not a chart of case data
TargetDiscord
ActorUnattributed
D. Kennedy9 min readConfidence: high2 sources reviewed

Discord notified users in May 2023 that an unauthorised party had gained access to the support ticket queue of an agent working for a third-party customer service provider. The company disabled the account, deactivated it and ran malware checks on the affected machine.

Discord told affected users it was possible their email address, the contents of customer service messages exchanged with Discord, and any attachments sent as part of those tickets had been exposed.

A Ticket Queue Is A Confession Log

People write to support when something has gone wrong, and they explain it. A support queue therefore holds accounts of problems, in the user’s own words, attached to their email address — and whatever screenshots or documents they thought would help.

The corpus records the same category at 23-1020, where HAR files uploaded to Okta’s support system carried live session tokens, and at 25-0826, where API tokens reached Cloudflare cases because customers pasted them. Support systems accumulate whatever people send under pressure.

The Account Was Not Discord’s

The compromised credential belonged to an agent at an outsourced provider. Discord could disable the account and notify users; it could not have patched the machine, chosen the provider’s controls or monitored the agent’s device.

The corpus files customer support as a recurring route at 25-1004b, where it appears in four separate incidents across four sectors in one year, and at 25-1003b for Discord itself later. Outsourced support is a standing grant of access to user correspondence held by a company the user has never heard of.

Small, And Worth Recording

This is a SEV 2 file. No identity documents, no financial data, no scale figure, and the company disclosed and contained it quickly.

It is here because the corpus is trying to be a record rather than a highlight reel, and because the mechanism — one agent account at one vendor, holding correspondence for an unknown number of users — recurs at much larger scale elsewhere in this database.

How we reported this

Built on Discord’s own notice on the incident and on contemporaneous reporting of the user notification. The compromise of a third-party support agent’s account, the categories of potentially exposed data and the response actions are Discord’s own statements. No number of affected users is asserted; Discord did not publish one. Reporting on a separate, later Discord incident involving a third-party support provider describes identity-document exposure at a stated scale; that is a different incident and none of its figures are carried here. No actor attribution is made. Graded high on Discord’s notice. Corrections: corrections@forensicpost.com.

Sources
  1. Update on a Security Incident Involving Third-Party Customer ServiceDiscord
  2. Discord discloses data breach after support agent got hackedBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary