Discord: 78M Discord files peddled online: Is the data leak real?

Discord: 78M Discord files peddled online: Is the data leak real?

Massive Discord Data Leak Claims Surface as Hackers Offer 78 Million Records

A cybercriminal group known as HawkSec has claimed responsibility for a massive data leak involving Discord, alleging the theft of 78 million records from the platform’s servers. The attackers stated the database was compiled over several months as part of an internal project to develop a Discord intelligence platform, though they later abandoned the effort.

The leaked data reportedly includes user profiles, voice session logs (207 million), files, and linked accounts such as Steam, raising concerns over potential doxxing, SWATing, impersonation, and account takeovers. While the group initially sought to sell the data, they later shifted their narrative, claiming they would share it with French authorities to combat illegal activities like CSAM, terrorism, and criminal networks.

Despite the bold claims, cybersecurity researchers remain skeptical. The attackers have reuploaded their forum post multiple times, adding details about the operation’s leadership, yet they have not provided verifiable samples of the data. Discord, which has over 200 million active users, has faced previous issues with harassment and targeted attacks, making the alleged breach particularly concerning.

The incident follows the emergence of Spy.Pet, a controversial tool that previously scraped billions of public Discord messages, offering them for AI training allegedly to federal agencies. HawkSec’s latest post suggests the breach extended beyond public servers, though the lack of evidence has led experts to question whether the leak is legitimate or an elaborate scam.

Discord has not yet responded to requests for comment. The situation remains under scrutiny as security analysts assess the validity of the claims.

Source: https://cybernews.com/security/discord-data-leak-claims/

Discord cybersecurity rating report: https://www.rankiteo.com/company/discord

"id": "DIS1768672125",
"linkid": "discord",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '78 million records allegedly '
                                              'exposed',
                        'industry': 'Technology (Communication Platform)',
                        'name': 'Discord',
                        'size': '200+ million active users',
                        'type': 'Company'}],
 'attack_vector': 'Unknown (allegedly compiled over several months)',
 'data_breach': {'data_exfiltration': 'Alleged',
                 'number_of_records_exposed': '78 million (alleged)',
                 'personally_identifiable_information': 'Yes (user profiles, '
                                                        'linked accounts)',
                 'sensitivity_of_data': 'High (potential for doxxing, SWATing, '
                                        'impersonation)',
                 'type_of_data_compromised': ['User profiles',
                                              'Voice session logs (207 '
                                              'million)',
                                              'Files',
                                              'Linked accounts (e.g., Steam)']},
 'description': 'A cybercriminal group known as HawkSec has claimed '
                'responsibility for a massive data leak involving Discord, '
                'alleging the theft of 78 million records from the platform’s '
                'servers. The leaked data reportedly includes user profiles, '
                'voice session logs (207 million), files, and linked accounts '
                'such as Steam, raising concerns over potential doxxing, '
                'SWATing, impersonation, and account takeovers. The attackers '
                'initially sought to sell the data but later claimed they '
                'would share it with French authorities to combat illegal '
                'activities like CSAM, terrorism, and criminal networks. The '
                'incident remains unverified due to lack of evidence.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'data exposure concerns',
            'data_compromised': '78 million records (user profiles, voice '
                                'session logs, files, linked accounts)',
            'identity_theft_risk': 'High (doxxing, SWATing, impersonation, '
                                   'account takeovers)',
            'systems_affected': 'Discord servers'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Initially sought, later '
                                                    'abandoned',
                           'reconnaissance_period': 'Several months (alleged)'},
 'investigation_status': 'Under scrutiny (validity of claims questioned)',
 'motivation': ['Data Theft',
                'Potential Financial Gain',
                'Combating Illegal Activities (claimed)'],
 'references': [{'source': 'Cybersecurity news reports'}],
 'threat_actor': 'HawkSec',
 'title': 'Massive Discord Data Leak Claims Surface as Hackers Offer 78 '
          'Million Records',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.