logo

Discord Zendesk breach highlights growing risk of third-party vendor access

ID: 315650af-c9f6-5598-9b96-9422ee9045b2

STIX ID: report--315650af-c9f6-5598-9b96-9422ee9045b2

Feed Name: ThreatLocker Blog

Threat Score
65/100

Date Published: 2026-02-19

Date Updated: 2026-05-01

...
...

**Executive Summary:** In October 2025, attackers abused legitimate credentials or sessions to access Discord’s third-party Zendesk support environment, exposing support tickets and identity verification documents for about 70,000 users while Discord reported its core authentication systems were not affected. The report assesses identity-theft and targeted-phishing risks, regulatory and reputational impacts, and recommends mitigations such as phishing-resistant MFA (FIDO2/WebAuthn), strict least-privilege access, vendor security assessments, data retention limits, behavioral monitoring, and third-party incident response playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.