Discord notified users in May 2023 that an unauthorised party had gained access to the support ticket queue of an agent working for a third-party customer service provider. The company disabled the account, deactivated it and ran malware checks on the affected machine.
Discord told affected users it was possible their email address, the contents of customer service messages exchanged with Discord, and any attachments sent as part of those tickets had been exposed.
A Ticket Queue Is A Confession Log
People write to support when something has gone wrong, and they explain it. A support queue therefore holds accounts of problems, in the user’s own words, attached to their email address — and whatever screenshots or documents they thought would help.
The corpus records the same category at 23-1020, where HAR files uploaded to Okta’s support system carried live session tokens, and at 25-0826, where API tokens reached Cloudflare cases because customers pasted them. Support systems accumulate whatever people send under pressure.
The Account Was Not Discord’s
The compromised credential belonged to an agent at an outsourced provider. Discord could disable the account and notify users; it could not have patched the machine, chosen the provider’s controls or monitored the agent’s device.
The corpus files customer support as a recurring route at 25-1004b, where it appears in four separate incidents across four sectors in one year, and at 25-1003b for Discord itself later. Outsourced support is a standing grant of access to user correspondence held by a company the user has never heard of.
Small, And Worth Recording
This is a SEV 2 file. No identity documents, no financial data, no scale figure, and the company disclosed and contained it quickly.
It is here because the corpus is trying to be a record rather than a highlight reel, and because the mechanism — one agent account at one vendor, holding correspondence for an unknown number of users — recurs at much larger scale elsewhere in this database.
Built on Discord’s own notice on the incident and on contemporaneous reporting of the user notification. The compromise of a third-party support agent’s account, the categories of potentially exposed data and the response actions are Discord’s own statements. No number of affected users is asserted; Discord did not publish one. Reporting on a separate, later Discord incident involving a third-party support provider describes identity-document exposure at a stated scale; that is a different incident and none of its figures are carried here. No actor attribution is made. Graded high on Discord’s notice. Corrections: corrections@forensicpost.com.