A compromised support agent, massive consequences

In April 2024, Discord publicly acknowledged a data leak after a customer support agent had their account compromised, likely through a social engineering attack. The attacker was able to access the internal support ticket management tool, which contained assistance requests submitted by users — including, in some cases, uploaded identification for verification purposes (ID cards, passports, driver's licenses).

Discord quickly revoked the compromised agent's access and notified the affected users, but the damage was already done: the exfiltrated data later appeared on darknet forums and clandestine Telegram channels.

Identification documents freely sold on the darknet

According to several cybersecurity analysts monitoring the underground forums following the incident, batches of data from the Discord leak — including copies of ID cards and other identification documents — were circulated. These documents reportedly came from support tickets in which users had provided their ID to:

  • Verify their age
  • Recover a hacked account
  • Prove their identity in a dispute

The dissemination of these documents is particularly concerning. An ID card alone can allow a cybercriminal to:

  • Open fraudulent accounts (online banks, crypto-exchanges, telecom operators)
  • Bypass KYC procedures (Know Your Customer)
  • Impersonate the victim for administrative processes
  • Conduct targeted phishing attacks with verified personal information

Why are these documents found in support tickets?

Discord, like many platforms, occasionally requests users to provide an ID to verify their identity, especially in cases of account recovery or disputes. These documents are theoretically stored securely within the ticket management system, but once the support tool is compromised, all tickets accessible to the compromised agent become vulnerable.

This is precisely the scenario that materialized: the attacker did not need to hack Discord's central servers; they merely needed to access the support tool with an agent's credentials to exfiltrate all associated tickets, including sensitive attachments.

Discord's reaction

Discord issued a notification to the affected users, indicating that the exposed data may include:

  • The email addresses associated with the accounts
  • The messages exchanged with support
  • The attachments submitted with the tickets, potentially including identification documents

The company stated it has strengthened its internal security measures, particularly by enforcing stricter multi-factor authentication (MFA) for its support agents and limiting access to sensitive attachments. Discord also indicated it was collaborating with authorities to investigate the incident.

Lessons to be learned

This incident highlights several recurring security issues:

  1. Never send identification documents via support tickets unless absolutely necessary. Prefer encrypted and official channels.
  2. Blur sensitive information on identification documents submitted online (numbers, barcodes) when possible.
  3. Monitor your digital identity: darknet monitoring services can alert you if your data appears in a leak.
  4. Enable MFA on all your online accounts, including Discord.

What to do if you are affected?

If you submitted an ID to Discord as part of a support ticket before April 2024, it is recommended to:

  • Monitor your bank accounts and report any suspicious activity
  • Request a renewal of your ID if you suspect it has been compromised
  • Activate fraud alerts with your bank and credit agencies
  • Check if your information is circulating on the darknet via specialized services like Have I Been Pwned

The Discord incident serves as a harsh reminder in cybersecurity: a chain of trust is only as strong as its weakest link. In this case, a simple compromised support agent was enough to expose thousands of identity documents to the underground web of the Internet.