In late 2025, a third-party customer support vendor Discord used for age appeals was breached. About 70,000 government ID photos were exposed. Names, emails, IP addresses, and support messages went with them. Attackers got in by targeting a support agent. Discord cut ties with the vendor and said the new partners were different. The leaked IDs are still out there.

They paused after the backlash
A few months later, Discord announced a global "teen-by-default" setup. Age-restricted channels and unblurred content would sit behind facial age estimation or an ID scan. Users remembered the last pile of documents that walked out the door and exploded. In February 2026, Discord delayed the worldwide age-assurance push until the second half of 2026.
Now they want another chance
That window is open now. Discord is bringing the checks back. It says more than 90 percent of users will never be asked. It says selfies stay on the phone. It says ID images get deleted fast. It says the new vendors were not involved in the 2025 leak. Those lines are the same comfort script every platform recites after it burns people.
Tech companies have a rotten record with this data. They collect it "just to confirm age," park it with a contractor, then act shocked when the contractor gets phished. You cannot recall a passport photo once it is stolen. You cannot unsell a face scan after a vendor changes hands.
Protecting teens is a real debate. It is not a license to demand more identity files from a company that already lost tens of thousands of them. Treat every new scan as a permanent risk. The last breach already showed the price.




Comments