Connect with us

Technology

Discord confirms vendor breach exposed user IDs in ransom plot

Published

on

Discord confirms vendor breach exposed user IDs in ransom plot

NEWYou can now listen to Fox News articles!

In 2025, it feels like cybercriminals are winning while the world’s biggest data hoarders are losing. One by one, global giants are admitting they’ve been breached, from tech powerhouses like Google to insurance leaders such as Allianz and Farmers and even luxury brands like Dior. The latest company to report a breach is Discord. The popular chat platform confirmed that hackers gained access to a third-party customer support provider, 5CA, exposing user data including names, email addresses, limited billing details and even government ID images.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

MAJOR COMPANIES, INCLUDING GOOGLE AND DIOR, HIT BY MASSIVE SALESFORCE DATA BREACH

Hackers hit Discord’s support vendor, exposing sensitive user data worldwide. (Phil Barker/Future Publishing via Getty Images)

Advertisement

How the breach happened and what data was exposed

The company confirmed that the breach, which occurred on September 20, did not involve a direct attack on Discord’s servers. Instead, attackers gained unauthorized access to 5CA, one of Discord’s third-party customer service providers. This allowed them to view information from users who had reached out to Discord’s Customer Support or Trust & Safety teams.

Discord is a chat app primarily used by gamers, but it has expanded to various other communities, enabling text messages, voice chats and video calls. Some even use it as a replacement for Slack. The platform currently has a monthly user base of over 200 million. The data exposed included Discord usernames, real names, emails, limited billing details such as payment type and the last four digits of credit cards, IP addresses and messages exchanged with customer service agents. In some cases, government ID images provided for age verification were also compromised. Discord estimates that around 70,000 users globally may have had government ID photos exposed.

Reports suggest the attackers attempted to use this access to demand a ransom from Discord. Bleeping Computer reported that the Scattered Lapsus$ Hunters (SLH) threat group claimed responsibility for the attack earlier this month. This is the same group that claims to have access to over a billion Salesforce records and is demanding ransom for those as well.

JEEP AND CHRYSLER PARENT STELLANTIS CONFIRMS DATA BREACH

About 70,000 users had ID images stolen in the latest third-party data breach. (Tiffany Hagler-Geard/Bloomberg via Getty Images)

Advertisement

What Discord is doing now and what users should do next

Discord disclosed the incident 13 days later, on October 3. Since then, it has cut off the third-party support provider’s access, launched an internal investigation with a digital forensics team and started informing affected users. It also clarified that any communication about the breach will come only from noreply@discord.com and that it will never contact users by phone regarding this incident. The company added that some data remained safe: full credit card numbers, CCV codes, account passwords and activity outside of customer support conversations were not exposed.

Discord also stated that it has notified relevant data-protection authorities about the breach, is working closely with law enforcement and is auditing its third-party vendors to ensure they meet its enhanced security and privacy standards going forward.

A representative at Discord issued a statement, saying in part, “We want to address inaccurate claims by those responsible that are circulating online. First, as stated in our blog post, this was not a breach of Discord, but rather a third-party service we use to support our customer service efforts. Second, the numbers being shared are incorrect and part of an attempt to extort a payment from Discord. Of the accounts impacted globally, we have identified approximately 70,000 users that may have had government-ID photos exposed, which our vendor used to review age-related appeals. Third, we will not reward those responsible for their illegal actions. All affected users globally have been contacted, and we continue to work closely with law enforcement, data protection authorities and external security experts. We’ve secured the affected systems and ended work with the compromised vendor. We take our responsibility to protect your personal data seriously and understand the concern this may cause.”

Discord cuts ties with vendor 5CA and tightens its security investigations. (Kurt “CyberGuy” Knutsson)

6 steps you can take to stay safe after the Discord breach

If you think your details might have leaked in the Discord data breach, below are some steps you can take to stay protected.

Advertisement

1) Enable two-factor authentication

Two-factor authentication (2FA) adds an extra verification step when logging in, making it much harder for attackers to access your account even if they have your password. Discord supports 2FA via authenticator apps or SMS. Once enabled, you’ll receive a code each time you log in from a new device. This simple step can prevent account takeovers and gives you peace of mind.

2) Consider a personal data removal service

The less information available about you, the harder it is for attackers to target you. Review what personal details you’ve shared online, and remove unnecessary data from websites and apps. A personal data removal service can help scrub your information from data broker sites, making it more difficult for attackers to connect the dots and launch identity theft or phishing attacks.

While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

Advertisement

3) Use strong, unique passwords for all accounts

Reusing passwords across platforms makes it easy for attackers to access multiple accounts if one password is compromised. A password manager can generate long, complex passwords and store them securely, so you don’t have to remember them all. This not only protects your Discord account but also your email, banking and other online services.

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords, and secure those accounts with new, unique credentials. 

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

4) Monitor accounts for suspicious activity

Even if you don’t see immediate signs of compromise, attackers can try to exploit stolen data later. Regularly check your email and Discord login history for unusual sign-ins. Services like identity theft protection can scan the dark web for your credentials and alert you immediately if they appear, helping you react quickly before serious damage occurs.

Identity Theft companies can monitor personal information like your Social Security Number (SSN), phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals. 

Advertisement

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

5) Be cautious with emails, messages or links, and use strong antivirus software

Phishing attacks often spike after breaches. Attackers may send messages that look like official notifications asking you to reset your password or provide personal information. Always verify the sender, avoid clicking unknown links, and never share sensitive info. Treat every unexpected message as suspicious, even if it appears to come from Discord or another trusted service.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com. 

6) Keep devices and software up to date

Attackers often exploit outdated software and known vulnerabilities. Ensure your operating system, apps and antivirus software are current.

Advertisement

 

Kurt’s key takeaway

If the recent breaches are any indication, third-party services that companies rely on are often the weakest link in cybersecurity. Discord’s steps to contain the situation are necessary, but they highlight a bigger problem. Many companies do not implement sufficient safeguards to protect sensitive user data. Weak oversight of third-party providers, delayed responses and inadequate security policies leave personal information exposed and vulnerable to attackers.

Should companies be held more accountable for breaches caused by third-party providers? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

Advertisement

Copyright 2025 CyberGuy.com. All rights reserved.

Technology

Valve is so behind on Steam Controller orders that some won’t ship until 2027

Published

on

Valve is so behind on Steam Controller orders that some won’t ship until 2027

Valve has some good news and bad news about Steam Controllers. The good news: if you make a reservation for a Steam Controller, the company will now show you one of three estimates of when you’ll be able to actually order your gamepad: by September 2026, by December 2026, or sometime in 2027. The bad news: any reservations made today “indicate a 2027 date for shipping,” Valve says.

“We have no plans to stop making Steam Controller,” according to Valve. “But as we look at the current demand compared to how many we know we can make by the end of the year, we want to manage expectations as much as we can with regards to when folks can expect to receive their order.”

Valve’s very good new Steam Controller went on sale in early May, and the initial rush led some people to run into frustrating problems with trying to check out ahead of the controllers eventually going out of stock. A few days later, the company announced that it would be implementing a reservations queue for interested buyers so they could get on a waitlist. If you’re on the waitlist, when you get notified that a Steam Controller is ready for you to buy, you have 72 hours to actually make the order.

“When we launched Steam Controller last month, we quickly saw that initial demand exceeded our expectations,” Valve says. “Switching to a reservation queue has (hopefully) cut down on the headaches on the customer side, and for us it’s also been helpful as we plan ahead and try to get as many out as quickly as we are able.”

All three of Valve’s big hardware products were delayed from a planned early 2026 launch because of the component crisis, Valve still hasn’t announced when the Steam Machine PC or Steam Frame VR headset might go on sale. However, just yesterday, Valve officially launched its big SteamOS 3.8 update with support for the Steam Machine. It’s also been importing a lot of hardware into the US as of late.

Advertisement
Continue Reading

Technology

McDonald’s AI drive-thru may take your next order

Published

on

McDonald’s AI drive-thru may take your next order

NEWYou can now listen to Fox News articles!

The next time you pull up to a McDonald’s drive-thru, the voice taking your order may not be human. McDonald’s is testing a new AI-powered system called ArchIQ at five U.S. locations. The company has not said where those restaurants are located. The voice assistant, nicknamed Archy, can take drive-thru orders and has shown it can handle both English and Spanish.

For anyone who has repeated “no pickles” into a speaker box more than once, this could sound helpful. However, if you remember McDonald’s last AI drive-thru experiment, you may also wonder whether your burger order could somehow turn into a bag full of surprise McNuggets.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.

Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

WOULD YOU EAT AT A RESTAURANT RUN BY AI? 

Advertisement

McDonald’s is testing an AI drive-thru system called ArchIQ at five U.S. restaurants. (Kurt “CyberGuy” Knutsson)

 

What is McDonald’s AI drive-thru?

ArchIQ is McDonald’s new AI system for restaurants. It can take drive-thru orders and also help with operations behind the scenes.

In a post on X, McFranchisee, an anonymous McDonald’s franchisee account, said the system is currently in five test stores and has processed more than one million transactions. The account also said about 90% of orders were completed without a human stepping in. That number sounds promising. Still, McDonald’s has not confirmed a nationwide launch date. For now, this remains a limited test.

The system also appears to connect with a bigger McDonald’s plan called “McDonald’s > NEXT.” CEO Chris Kempczinski described the strategy as a way to bring in more customers and improve restaurant productivity. The plan also includes menu changes, restaurant redesigns, technology upgrades and more focus on hospitality.

 

Why McDonald’s is testing AI ordering

Drive-thrus can get chaotic fast. Someone changes an order after the total appears. A child calls out from the back seat. Road noise makes the speaker hard to hear. Then the driver remembers the extra sauce after everything has already gone through. That is the type of pressure McDonald’s wants AI to handle.

Advertisement

If ArchIQ works well, it could help restaurants move cars through the line faster. It may also reduce mistakes during busy hours. Workers could then focus more on preparing food, handling payments and helping customers who need a real person.

ArchIQ also appears to have a management role. In the same X post, McFranchisee described Archy as a tool that could alert managers to bottlenecks or other issues before they slow down operations. 

STARBUCKS USES CHATGPT TO SUGGEST DRINKS BASED ON MOOD AS EXPERT WARNS OF HIDDEN DOWNSIDES

The AI assistant, nicknamed Archy, can take drive-thru orders and may also help managers spot restaurant slowdowns. (McFranchisee)

 

McDonald’s tried AI drive-thru ordering before

This new test follows McDonald’s earlier AI drive-thru experiment with IBM. That program involved more than 100 restaurants. McDonald’s ended the test in 2024 after customers complained about order accuracy. Some mistakes also went viral, creating an embarrassing moment for McDonald’s and raising questions about whether the technology was ready for the drive-thru. Customers reported wrong items, strange quantities and other order mix-ups. That history is why this new test will get extra attention.

Advertisement

This time, McDonald’s is working with Google technology. McFranchisee also claimed every McDonald’s in the U.S. is getting Google Edge Cloud hardware in anticipation of the rollout. McDonald’s seems to believe the newer system can perform better than the last one. The real test will come when regular customers use it during real drive-thru rushes.

 

How McDonald’s AI drive-thru could help customers

If McDonald’s gets this right, the most obvious benefit is speed. An AI ordering system does not get tired during a long shift. It may also help more customers order in the language they prefer. That could make a busy drive-thru feel less frustrating, especially during breakfast or late-night hours.

The system may also ask clearer follow-up questions and catch missing details before the order reaches the kitchen. That would be a win for customers who want to get in, get their food and get on with the day.

 

The biggest problem with AI drive-thru orders

The biggest concern is accuracy. AI can still misunderstand people. That gets frustrating fast when you are trying to grab lunch between errands or get your kids fed from the back seat. A wrong order wastes time. It also puts workers in the position of fixing a mistake the machine made.

There is also the customer service side. Some people like hearing a real person at the speaker. Others may find an AI voice cold or annoying, especially if the system gets confused.

Advertisement

Then there is the privacy question. If an AI system takes your order, customers may wonder what gets collected, how long it is kept and who can access it. McDonald’s has not publicly explained those specifics for this current ArchIQ test.

ALEXA+ LETS YOU ORDER FOOD LIKE A REAL CONVERSATION

A drive-thru menu board stands outside a McDonald’s restaurant in Hercules, Calif., on Oct. 23, 2024, amid an E. coli outbreak linked to onions in Quarter Pounder sandwiches that has sickened dozens and killed one person across the U.S. (David Paul Morris/Bloomberg via Getty Images)

 

How to avoid AI drive-thru mistakes

Before you leave the drive-thru, take a moment to check the order screen. Make sure the items match what you said. Listen when the system repeats your order. Keep your receipt until you confirm the food is right.

Also, avoid sharing extra personal details at the speaker box. Your order should only require your food choices and payment.

Advertisement

If the AI gets confused, ask for a crew member. You do not need to keep going back and forth with a machine over fries.

 

What this means for you

For now, you probably will not notice a change at your local McDonald’s. The ArchIQ test appears limited to five U.S. restaurants, and the company has not said when it could expand.

Still, this gives customers a preview of where fast food may be heading. AI could soon play a bigger role in how restaurants take orders and manage the kitchen. That may speed up the line, though it could also make the experience feel less personal.

 

Watch the CyberGuy Live replay: Lock Down Your Phone in 30 Minutes

Your phone holds your email, passwords, photos, banking apps and personal data. In this free CyberGuy Live replay, Kurt the CyberGuy walks you step by step through simple phone security fixes you can do at your own pace. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Watch the replay and get our checklist here: CyberGuyLive.com

 

Kurt’s key takeaways

McDonald’s clearly wants AI to play a bigger role in its restaurants. From a business point of view, the idea makes sense. Shorter drive-thru lines could help franchisees and customers. Better restaurant data could also help managers fix problems faster. But I still want the human backup. Food orders can be messy because people are messy. We change our minds. We talk over each other. We forget the extra ketchup until the last second. AI may handle much of that one day. For now, I would treat it like any busy drive-thru interaction. Speak clearly. Check the order. Do not pull away until you know your food is right.

Advertisement

Would you trust an AI voice to take your McDonald’s order, or do you still want a real person on the other end of the speaker? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Midjourney goes from generating cat images to full-body ultrasound scans

Published

on

Midjourney goes from generating cat images to full-body ultrasound scans

Midjourney CEO David Holz just showed off the company’s first hardware product and plans to build a San Francisco spa, which he admitted is a bit different from the “cat pictures” produced by its AI image generator. Dubbed The Midjourney Scanner, it’s an ultrasound-based full-body scanner that uses a ring of sensors to capture vertical slices of the inside of your body, looking at the composition of your muscle, fat, bone, and organs to start. Holz said ideally, you could do this once a year or every single day, as it “aims for image quality comparable to MRI in many ways.”

He mentioned that one way he’d like to use it would be to see how his body changes in response to diet and workout changes, saying, “I’m not the most measured man on Earth yet, you know, but maybe I want to have that daily [measurable information].” A set of job listings advertises the company’s goal as trying to “build and launch the world’s first full-body ultrasound CT scanner, ultimately bringing safe, fast, and high fidelity preventative scanning to billions via a magical spa experience.”

The Midjourney Scanner was developed in a partnership with ultrasound tech company Butterfly Network, which said it uses “40 Butterfly Ultrasound-on-Chip imaging modules per system.”

The scanning process starts with stepping onto a platform that drops down into the water on rails through a ring of thousands of transducers that create ultrasonic waves. It then records the ripples passing through your body to analyze them and create detailed 3D images. The scan takes about 60 seconds. Holz said about a dozen people have been scanned so far.

It starts by stepping into a shallow pool of golden light. You then begin to descend into the water. Your body passes through a ring of underwater sensors, each acting like a dolphin, using its echolocation. The sensors send ultrasonic sound waves through your body from every angle. With enough waves, and enough angles, we form an image of what’s happening inside your body.

It combines those sensors with two petaflops of processing power. But after watching the livestreamed reveal, I’m still unclear on what Midjourney’s AI image generation tech exactly has to do with the Midjourney Medical effort, beyond an alternative business for otherwise-unused AI compute.

Advertisement

Holz hopes to put 10 of the scanners into a Midjourney Spa location in San Francisco’s Union Square that will open before the end of 2027 and offered to scan the hands of attendees at its launch event. The Midjourney Spa will have a gym, saunas, and cold plunges to go along with the hot tub–equipped scanning rooms where visitors will get into the water to be scanned.

He did mention that various medical applications would require FDA clearances, but for now, Midjourney Medical says it’s working on “body composition maps” that don’t require the same level of clearance as diagnostic imaging. It also says the “library of scans” users create can be shared with doctors, AI health tools, or others, and that, “We take data privacy seriously — more details on our data policies will come as we get closer to launch.”

Holz suggested that eventually these scans could become better than an MRI, without radiation, powerful magnets, or other complicating factors, to get a look at what’s going on inside people’s bodies “real fast.” In response to a question, he imagined a future where the FDA had a class of devices to look at “weird” things and allowed people to “just try to get as much data as we can.”

Continue Reading
Advertisement

Trending