Desk live·
ForensicPost
Cloud/Third party/File 25-1003b

Discord Breach Reached Billing Details via Third-Party Support Provider

Discord disclosed that attackers reached user IDs, billing details and support conversations through a third-party customer service provider.

Constructed geometry · not a chart of case data
TargetDiscord
ActorUnattributed
S. Rosler12 min readConfidence: medium2 sources reviewed

Discord disclosed that an unauthorised party had accessed user IDs, billing details and support chat records through a third-party customer service provider.

Support Conversations Are An Underrated Data Class

A support ticket is what a person wrote when they needed help. It contains the problem in their own words, whatever they attached to prove it, and the agent’s notes.

This desk filed at 25-0826 that a hundred and four API tokens sat in support tickets, and at 25-1006 that CRM free-text notes are uninventoried because the field is called "notes". Support histories are the consumer version: a repository nobody classifies, containing whatever users happened to send.

And Outsourced Support Is Now A Recurring Route

Coinbase at 25-0514, where attackers recruited overseas support agents rather than breaking in. PowerSchool at 25-0105, where a support portal led to the student information system. The consent-phishing campaign at 25-0806, which targeted service desks across four sectors.

The pattern is consistent enough to state plainly: the support function is where an organisation’s data is most accessible and least defended, because its purpose is to give people access to things.

The Economics Explain It

Support is a cost centre. It is outsourced to reduce that cost, to providers competing on price, staffed accordingly — the argument at 25-0514, where a support agent’s salary was an amount an attacker could beat with a single payment.

The data those agents can reach is not reduced correspondingly. An organisation optimises the cost of the function and not the exposure of the access.

Graded medium: the mechanism and the affected volume are not established, and the provider is not named in the material we reviewed.

How we reported this

Compiled from published reporting, listed below. The provider, the mechanism and the affected volume are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Inside the biggest cyber attacks of 2025Security Boulevard
  2. Gaming and entertainment data breachesClass Action U
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary