Discord has identified 5CA, a Dutch company, as the vendor responsible for the data breach that exposed information and ID photos of over 70,000 users worldwide.
However, 5CA denies any wrongdoing, stating that its systems have not been hacked.
On October 3, 2025, Discord announced that an unauthorized party had gained access to one of its third-party customer service providers, affecting users who had interacted with Customer Support or Trust & Safety.
In an updated statement on October 9, Discord formally named 5CA, a Netherlands-based customer experience firm, as the provider involved in the data breach.
The attackers, known as the Scattered Lapsus$ Hunters (SLH), allegedly breached 5CA's support ticket environment and took 1.6 terabytes of data.
The attackers identified themselves as the Scattered Lapsus$ Hunters (SLH).
Author's summary: Discord names 5CA as responsible for the data breach.