Patreon Logo Support us on Patreon to keep GamingOnLinux alive. This ensures all of our main content remains free for everyone. Just good, fresh content! Alternatively, you can donate through PayPal Logo PayPal. You can also buy games using our partner links for GOG and Humble Store.
We use affiliate links to earn us some pennies. Learn more.

Around 70,000 users affected in Discord related breach which includes some government ID images

By -
Last updated: 10 Oct 2025 at 11:13 am UTC

Ouch. This whole ongoing online safety thing is going well isn't it? Who could have guessed that some personal data would end up leaking? Everyone with a brain that even remotely understands the internet and technology.

Discord recently announced on October 3rd that a partner they were using for third-party customer service had been compromised. The attackers managed to swipe the likes of contact details, limited billing info, IP addresses, messages with customer service agents, limited corporate data and a "small number of government‑ID images".

Originally the article did not name the company involved, or how many were affected, but it was updated on October 9th to clarify after some misinformation spread online and named "5CA" as the company that was compromised. That and they also now note more clearly that "approximately 70,000" had their government ID photos exposed".

This is all to do with Discord's requirement to verify the age of people in some countries, but this is specifically to do with those who went through customer service for age-related appeals. So to be clear, Discord itself was not compromised, the third-party 5CA were the issue.

A thoroughly frustrating issue. One not just localised to the UK with the Online Safety Act, as more countries and US states have been slowly pushing out age verification requirements to various platforms. This issue of security and privacy is only going to get worse as time goes on. These laws have just added an extra burden to everyone, and made an even bigger target for bad actors to grab even more sensitive personal data from people.

Article taken from GamingOnLinux.com.
Tags: Security, Apps, Misc
4 Likes
About the author -
author picture
I am the owner of GamingOnLinux. After discovering Linux back in the days of Mandrake in 2003, I constantly checked on the progress of Linux until Ubuntu appeared on the scene and it helped me to really love it. You can reach me easily by emailing GamingOnLinux directly.
See more from me
All posts need to follow our rules. Please hit the Report Flag icon on any post that breaks the rules or contains illegal / harmful content. Readers can also email us for any issues or concerns.
15 comments Subscribe

greylock 6 hours ago
User Avatar
Well that didn't take long! Who could have ever seen this coming? emoji
tfk 6 hours ago
User Avatar
Wait a minute. Something just occurred to me. What if this wasn't about our safety to begin with? emoji
sherriw 5 hours ago
Why on earth do these sites keep the ID scans?? Validate the user, save the date date and a 'yes valid' checkmark. Then delete the damn id.
Stella 5 hours ago
User Avatar
Why on earth do these sites keep the ID scans?? Validate the user, save the date date and a 'yes valid' checkmark. Then delete the damn id.

that's what discord claimed it is doing, but this incident has exposed it as one fat lie.

Q: Is my data stored when I use Face Scan or Scan ID verification?

A: Discord and k-ID do not permanently store personal identity documents or your video selfies. The image of your identity document and the ID face match selfie are deleted directly after your age group is confirmed, and the video selfie used for facial age estimation never leaves your device.

Chrisznix 5 hours ago
User Avatar
One reason i set up a murmur server for voice chat for me & my friends, but i totally failed to get my kids (and their friends) away from discord because eeeeveryone seems to use it. I personally really hate the UI, its confusing for me (hell its almost as bad as MS Teams!), but they dont seem to mind.
Daddy and his old worn-out privacy concerns. Sigh.
TheSHEEEP 5 hours ago
  • Supporter Plus
Why on earth do these sites keep the ID scans?? Validate the user, save the date date and a 'yes valid' checkmark. Then delete the damn id.
That is really the biggest wtf of this whole thing.

Age verification? Sure, do it.
In fact, should just be mandatory to access social media at this point (fully on board with Australia's plan here).

But there are honestly drastically better ways to do this than scanning and sending government IDs.
Such as how this has been done for many, many years in Finland for example. There are several ways to confirm your identity, often through your banking or mobile providers.
Those can confirm (after 2FA in general) that you are you and they could say "yes" or "no" when asked "is this person age X+?". No scanning, no webcam crap to compare ID and picture, just call an API with minimal data and get an answer to your query.

But even if you did it the oldschool way with government ID scanning - why the hell store them? That is just gross negligence.

Daddy and his old worn-out privacy concerns. Sigh.
Think your kids might be right here.
There is no way your data is fully safe anywhere - you'd have to be off the grid, essentially, to achieve that.
And since that is the case, quite frankly: Why bother?

Take this very example, right?
So now some actors could find out person X has authenticated themselves on Discord.
Oh no, the horror.

Be reasonable with what you share of yourself in public (or semi-public) spaces and you'll be fine.
Because eventually, your data can and will very likely leak and your "anonymity" will be gone.
That's a much better lesson to teach kids than appear all tinfoil hat to them with cumbersome "solutions".


Last edited by TheSHEEEP on 10 Oct 2025 at 12:30 pm UTC
Pyrate 5 hours ago
User Avatar
Highly disagree with the comment above mine. Every bit towards claiming one's privacy helps. It's not an all or nothing deal, where you should just give up and 'why bother'.

Additionally, Discord fucking sucks even without the privacy concerns, and is an actual hazard with them. The sooner we get a proper alternative that can be convincing for peers to jump ship, the better.
tfk 4 hours ago
User Avatar
Why on earth do these sites keep the ID scans?? Validate the user, save the date date and a 'yes valid' checkmark. Then delete the damn id.

Hi! My name is Fred and I'm the CEO of a very large advertising agency. I would like to thank you for your very generous donation. Really, your information is worth millions to us. So thank you again for making sure I can keep living in my very large beach house in Florida and for making sure I can keep driving my Ferrari's!
Lofty 4 hours ago
Age verification? Sure, do it.
In fact, should just be mandatory to access social media at this point (fully on board with Australia's plan here).

Think your kids might be right here.
There is no way your data is fully safe anywhere - you'd have to be off the grid, essentially, to achieve that.And since that is the case, quite frankly: Why bother?
That's a much better lesson to teach kids than appear all tinfoil hat to them with cumbersome "solutions".

You are really living upto your username there Mr Sheep emoji
fabertawe 3 hours ago
Imagine the treasure trove up for grabs if digital IDs were to be implemented in the UK. And it will be grabbed, 100%. Hopefully the backlash against this will prove overwhelming and sanity will prevail.
Lofty 3 hours ago
Imagine the treasure trove up for grabs if digital IDs were to be implemented in the UK. And it will be grabbed, 100%. Hopefully the backlash against this will prove overwhelming and sanity will prevail.

just another tick box to add to your personal insurance plan for identity theft protection. That way companies benefit from the theft on both ends.
pb 3 hours ago
User Avatar
BUT WILL ANYONE THINK OF THE CHILDREN?!
GoEsr 3 hours ago
User Avatar
BUT WILL ANYONE THINK OF THE CHILDREN?!
And their parents whose IDs they stole.
Pikolo 2 hours ago
@fabertawe A well designed Digital ID would result in something exactly opposite - instead of every entity accessing your Identity getting full details, there would be an "isOver18" API they could query. Hopefully you'd authenticate yourself to Discord with a one-time token rather than sharing your real name.

Whether we would get a well designed API, I don't know. But without a proper digital ID, we will keep getting passport photos used for age and identify verification
fabertawe 50 minutes ago
@Pikolo - "A well designed Digital ID would result in something exactly opposite"

Unfortunately, the UK government's idea of "well designed" is the antithesis of what would be useful to it's citizens. It is purely about authoritarian control.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon Logo Patreon. Plain Donations: PayPal Logo PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register