The Containment Era is here. →Explore

Executive Summary

In late September 2025, attackers compromised a support agent account at an outsourced BPO provider and gained unauthorized access to Discord’s Zendesk support platform for 58 hours. Exploiting privileged access, they exfiltrated up to 1.6 TB of data, including approximately 8.4 million support tickets affecting 5.5 million users, with sensitive information such as emails, Discord IDs, phone numbers, partial payment data, and around 70,000 government-ID photos. The threat group leveraged integrations between Zendesk and Discord’s internal systems, extracted additional user details via APIs, and attempted a multimillion-dollar ransom before threatening public data release.

This incident highlights the growing risk from third-party supply chain attacks targeting cloud-based customer support platforms and BPO providers. The attacker's tactics—abusing helpdesk integrations and privilege escalation—reflect broader cybercrime trends, including identity-driven attacks, data extortion, and rising regulatory scrutiny.

Why This Matters Now

With organizations increasingly reliant on external vendors for support operations, supply chain compromises pose significant risks to customer data and regulatory compliance. Robust third-party controls and privileged access management are now urgent priorities to reduce the attack surface for identity-driven breaches.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Exposed data included emails, Discord usernames and IDs, phone numbers, partial payment information, date of birth, government ID photos, and internal support details.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, granular policy enforcement, east-west traffic controls, and egress filtering could have contained the attack by restricting BPO agent session scope, detecting anomalous activity, and preventing large-scale data exfiltration beyond intended workflows.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Restricted support agent access to only their own customer tickets and functions.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Anomalous privilege usage detected and alerted in real time.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unauthorized internal movement restricted and detected.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Unusual query volume and persistent access patterns rapidly detected.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Automated blocking or throttling of large-scale data egress attempts.

Impact (Mitigations)

Containment of impact by minimizing breach scope and triggering rapid incident response.

Impact at a Glance

Affected Business Functions

  • Customer Support
  • Trust & Safety
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Approximately 70,000 users had their government-issued ID photos exposed, along with names, usernames, email addresses, IP addresses, and limited billing information.

Recommended Actions

  • Implement Zero Trust segmentation for all BPO and third-party identities, restricting access to the minimum needed data and systems.
  • Enforce granular egress policies to detect and block unauthorized large-scale data exports from SaaS or support platforms.
  • Deploy threat detection with baseline anomaly analytics to alert on suspicious privilege changes and excessive API usage.
  • Require strong MFA and session posture checks for all support and integrated SaaS accounts, especially for outsourced vendors.
  • Leverage multi-cloud visibility tools to continuously audit, monitor, and automate incident response across all support and customer-facing environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image