Weekly Backlog Week 44/2025
Editorial Germany, your servers. In the same week that a small community in Baden-Württemberg …

On October 5, 2025, it was revealed that an external support provider for the platform Discord was the target of a cyberattack. Personal data of users who had contacted Discord support in recent weeks was stolen. According to Discord, the core platform was not affected. The attack focused exclusively on the systems of the contracted service provider.
According to the company, the attackers were able to access the following data sets:
According to Discord, full credit card details and passwords were not affected. The platform emphasizes that no chat messages or content from the actual communication platform were accessed.
The attack was allegedly carried out by the group Scattered Lapsus$ Hunters. The attackers claimed to have successfully compromised a well-known service provider—presumably Zendesk. An official confirmation of the affected company’s name is still pending.
Even though only a portion of the user base is affected, security researchers warn of potential follow-up attacks, particularly in the area of phishing. With combinations of IP addresses, identification data, and support histories, convincing fraud attempts can be constructed, such as for supposed refunds or verifications.
Discord stated that the incident is “under control” and affected users would be contacted directly. How many people are affected has not yet been disclosed. It is also unclear over what period data was compromised.
According to the company, the following actions are currently underway:
Even though the Discord platform was not technically compromised directly, the incident highlights the growing importance of security requirements along the entire service chain. Particularly in the area of externally outsourced support, personal data is often more accessible, making it a larger target for attacks.
In the future, it will be crucial how platforms like Discord handle the insights from such incidents—especially regarding:
Affected users should be more vigilant about potential phishing attempts—especially with emails referencing recently contacted support inquiries. In general, the following applies:
Conclusion:
The data breach surrounding Discord once again shows how relevant security precautions are beyond the core systems. The protection of sensitive information does not end with the provider—it begins there.
Editorial Germany, your servers. In the same week that a small community in Baden-Württemberg …
What initially seemed like a manageable incident has now officially turned into a complete loss of …
Weekly Backlog Week 41/2025 Digital Identity, Sovereign Administrations, and the Unbreakable …