Technology
Discord confirms vendor breach exposed user IDs in ransom plot
NEWYou can now listen to Fox News articles!
In 2025, it feels like cybercriminals are winning while the world’s biggest data hoarders are losing. One by one, global giants are admitting they’ve been breached, from tech powerhouses like Google to insurance leaders such as Allianz and Farmers and even luxury brands like Dior. The latest company to report a breach is Discord. The popular chat platform confirmed that hackers gained access to a third-party customer support provider, 5CA, exposing user data including names, email addresses, limited billing details and even government ID images.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
MAJOR COMPANIES, INCLUDING GOOGLE AND DIOR, HIT BY MASSIVE SALESFORCE DATA BREACH
Hackers hit Discord’s support vendor, exposing sensitive user data worldwide. (Phil Barker/Future Publishing via Getty Images)
How the breach happened and what data was exposed
The company confirmed that the breach, which occurred on September 20, did not involve a direct attack on Discord’s servers. Instead, attackers gained unauthorized access to 5CA, one of Discord’s third-party customer service providers. This allowed them to view information from users who had reached out to Discord’s Customer Support or Trust & Safety teams.
Discord is a chat app primarily used by gamers, but it has expanded to various other communities, enabling text messages, voice chats and video calls. Some even use it as a replacement for Slack. The platform currently has a monthly user base of over 200 million. The data exposed included Discord usernames, real names, emails, limited billing details such as payment type and the last four digits of credit cards, IP addresses and messages exchanged with customer service agents. In some cases, government ID images provided for age verification were also compromised. Discord estimates that around 70,000 users globally may have had government ID photos exposed.
Reports suggest the attackers attempted to use this access to demand a ransom from Discord. Bleeping Computer reported that the Scattered Lapsus$ Hunters (SLH) threat group claimed responsibility for the attack earlier this month. This is the same group that claims to have access to over a billion Salesforce records and is demanding ransom for those as well.
JEEP AND CHRYSLER PARENT STELLANTIS CONFIRMS DATA BREACH
About 70,000 users had ID images stolen in the latest third-party data breach. (Tiffany Hagler-Geard/Bloomberg via Getty Images)
What Discord is doing now and what users should do next
Discord disclosed the incident 13 days later, on October 3. Since then, it has cut off the third-party support provider’s access, launched an internal investigation with a digital forensics team and started informing affected users. It also clarified that any communication about the breach will come only from noreply@discord.com and that it will never contact users by phone regarding this incident. The company added that some data remained safe: full credit card numbers, CCV codes, account passwords and activity outside of customer support conversations were not exposed.
Discord also stated that it has notified relevant data-protection authorities about the breach, is working closely with law enforcement and is auditing its third-party vendors to ensure they meet its enhanced security and privacy standards going forward.
A representative at Discord issued a statement, saying in part, “We want to address inaccurate claims by those responsible that are circulating online. First, as stated in our blog post, this was not a breach of Discord, but rather a third-party service we use to support our customer service efforts. Second, the numbers being shared are incorrect and part of an attempt to extort a payment from Discord. Of the accounts impacted globally, we have identified approximately 70,000 users that may have had government-ID photos exposed, which our vendor used to review age-related appeals. Third, we will not reward those responsible for their illegal actions. All affected users globally have been contacted, and we continue to work closely with law enforcement, data protection authorities and external security experts. We’ve secured the affected systems and ended work with the compromised vendor. We take our responsibility to protect your personal data seriously and understand the concern this may cause.”
Discord cuts ties with vendor 5CA and tightens its security investigations. (Kurt “CyberGuy” Knutsson)
6 steps you can take to stay safe after the Discord breach
If you think your details might have leaked in the Discord data breach, below are some steps you can take to stay protected.
1) Enable two-factor authentication
Two-factor authentication (2FA) adds an extra verification step when logging in, making it much harder for attackers to access your account even if they have your password. Discord supports 2FA via authenticator apps or SMS. Once enabled, you’ll receive a code each time you log in from a new device. This simple step can prevent account takeovers and gives you peace of mind.
2) Consider a personal data removal service
The less information available about you, the harder it is for attackers to target you. Review what personal details you’ve shared online, and remove unnecessary data from websites and apps. A personal data removal service can help scrub your information from data broker sites, making it more difficult for attackers to connect the dots and launch identity theft or phishing attacks.
While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com
3) Use strong, unique passwords for all accounts
Reusing passwords across platforms makes it easy for attackers to access multiple accounts if one password is compromised. A password manager can generate long, complex passwords and store them securely, so you don’t have to remember them all. This not only protects your Discord account but also your email, banking and other online services.
Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords, and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com
4) Monitor accounts for suspicious activity
Even if you don’t see immediate signs of compromise, attackers can try to exploit stolen data later. Regularly check your email and Discord login history for unusual sign-ins. Services like identity theft protection can scan the dark web for your credentials and alert you immediately if they appear, helping you react quickly before serious damage occurs.
Identity Theft companies can monitor personal information like your Social Security Number (SSN), phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.
5) Be cautious with emails, messages or links, and use strong antivirus software
Phishing attacks often spike after breaches. Attackers may send messages that look like official notifications asking you to reset your password or provide personal information. Always verify the sender, avoid clicking unknown links, and never share sensitive info. Treat every unexpected message as suspicious, even if it appears to come from Discord or another trusted service.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
6) Keep devices and software up to date
Attackers often exploit outdated software and known vulnerabilities. Ensure your operating system, apps and antivirus software are current.
Kurt’s key takeaway
If the recent breaches are any indication, third-party services that companies rely on are often the weakest link in cybersecurity. Discord’s steps to contain the situation are necessary, but they highlight a bigger problem. Many companies do not implement sufficient safeguards to protect sensitive user data. Weak oversight of third-party providers, delayed responses and inadequate security policies leave personal information exposed and vulnerable to attackers.
Should companies be held more accountable for breaches caused by third-party providers? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Acer’s launching a Linux handheld for streaming your PC games
The Acer Nitro Blaze Link might run on Linux, but it’s no Steam Deck. Acer says it’s a “streaming-first handheld and companion device,” like a PlayStation Portal for your PC. Announced ahead of Computex on Friday, it’s launching in Q4 2026 with a 7-inch (1920 x 1200) display, Wi-Fi 6, just 1GB of LPDDR4 RAM, and 8GB of eMMC storage. That’s technically not even enough RAM to run Stardew Valley, but the Blaze Link isn’t meant for playing games locally.
Logitech launched a similar handheld a few years ago, the Logitech G Cloud, that cost $350, included 4GB of RAM and 64GB of storage, and ran on Android. It was a tough sell at that price considering that its performance was dependent on a good internet connection.
Acer hasn’t yet announced a price for the Nitro Blaze Link. But its specs suggest it could cost significantly less than proper handheld gaming PCs — which have been skyrocketing in price — potentially offering a more affordable and streaming-first alternative.
Correction, May 29th: The Nitro Blaze Link was announced ahead of Computex 2026, not at it.
Technology
Fake grant email promises $4.5 Million but could steal your identity
NEWYou can now listen to Fox News articles!
It shows up in your junk folder with a subject line that practically yells at you: “ATTENTION 1!!!” That alone should raise suspicion. Still, the message quickly escalates. It claims to come from the IMF (International Monetary Fund) and says you are approved for a $4.5 million grant.
That is where things start to fall apart. This type of scam is designed to trigger both excitement and urgency. It also pushes you to hand over sensitive information before you stop to think.
Let’s break down exactly what this email says and why each part signals trouble.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
NEW EMAIL SCAM USES HIDDEN CHARACTERS TO SLIP PAST FILTERS
A fake IMF grant email promises millions of dollars while asking recipients to share personal details and identity documents. (Rawf8/Getty Images)
The sender behind this IMF scam email
The email claims to be from the IMF. Yet the reply address is a Gmail account. That mismatch matters.
Legitimate financial institutions do not use free email services for official communication. They also do not ask you to reply to a personal inbox for something this serious.
Why the subject line is a warning sign
“ATTENTION 1!!!” is not how a global financial organization communicates. It is how scammers try to grab you fast.
Urgency lowers your guard. When you feel pressure, you are more likely to respond without verifying anything.
The greeting reveals a mass email
The message opens with “Attention: Sir/Madam.” If your name were truly selected for a multimillion-dollar payment, the sender would use it.
Generic greetings often mean the email was blasted out to thousands of people.
How the story tries to hook you
The email mentions debts tied to contracts, inheritance, lottery and loans. That wide net is intentional.
It increases the odds that something in the message feels familiar. Once that happens, the scam starts to feel personal.
The $4.5 million promise is the bait
The promise of $4.5 million is not random. Large numbers create excitement. They also make you more willing to overlook obvious problems.
Real financial grants do not appear out of nowhere like this.
YOUR EMAIL DIDN’T EXPIRE; IT’S JUST ANOTHER SNEAKY SCAM
Scam emails may use real organization names, official titles and urgent language to pressure people into responding quickly. (Pekic/Getty Images)
Why scammers use real names
The email mentions IMF Managing Director Kristalina Georgieva. That sounds official, which is the point.
Scammers often include real names or titles to make fake messages feel credible. It is a shortcut to trust.
The writing and grammar feel off
Phrases like “Kindly reply me directly” and awkward sentence structure stand out. One odd sentence might not mean much. However, repeated issues like this point to a lack of professional communication.
Major institutions have strict standards for how they write.
The most dangerous request in this email
This email requests:
- Full name
- Address and location
- Phone number
- Age and occupation
- A copy of your passport or driver’s license
That is everything needed for identity theft. Once someone has those details, they can open accounts, target you with more scams or impersonate you.
The payment method adds false legitimacy
The email promises a bank-to-bank wire transfer. That detail adds a layer of realism. It also sets up the next step. Many scams later ask for “fees” to release the funds.
You send money, and the payment never arrives.
Even the spam excuse is part of the scam
At the end, the email tries to explain away the biggest red flag: “If you have received this message in your SPAM/BULK folder, it is simply because your ISP has introduced restrictions. We urge that you treat it as a matter of urgency.” That is not a reassurance. It is a warning sign.
Scammers know their messages look suspicious, so they try to explain it away before you question it.
THE ONE THING SCAMMERS CHECK BEFORE TARGETING YOU ONLINE
Users should delete suspicious grant emails, avoid links and verify claims directly through official organization websites. (Photographer: Wei Leng Tay/Bloomberg via Getty Images)
How to stay safe from scam emails
Scams like this follow a pattern, and once you know what to look for, you can shut them down quickly before any damage is done.
1) Ignore and delete the message
Do not reply or engage in any way. Even a quick response tells scammers your email is active, which can lead to more targeted attacks. The safest move is to delete it and move on.
2) Do not click links or download attachments
Scam emails often hide malicious links or infected files. One click can take you to a fake login page or install malware on your device. If you were not expecting the message, do not interact with anything inside it.
3) Use strong antivirus software
Strong antivirus software adds another layer of protection. It can flag suspicious emails, block dangerous websites and stop malicious downloads before they cause harm. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
4) Never send personal documents
No legitimate organization will ask for your passport, driver’s license or other sensitive documents through an unsolicited email. Sending that information can open the door to identity theft and financial fraud.
5) Look closely at the sender
Do not rely on the display name alone. Check the full email address carefully for misspellings, random numbers or free domains like Gmail. Small details often reveal a fake.
6) Go directly to official sources
If the message seems important, verify it on your own. Type the organization’s website into your browser or use a trusted contact method. Do not use the links or contact details provided in the email.
7) Remove your personal data from the internet
Scammers often rely on publicly available information to make their messages feel convincing. Data removal services can reduce what is out there, making it harder for criminals to target you in the first place. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
8) Turn on two-factor authentication
Add an extra layer of security to your accounts. With 2FA enabled, a stolen password alone is not enough for someone to get in. This simple step can stop many attacks before they start.
9) Monitor your financial accounts and credit
Check your bank statements and credit reports regularly. Look for unfamiliar charges, new accounts or changes you did not make. Catching fraud early can limit the damage.
10) Consider placing a credit freeze
If you think your personal information was exposed, a credit freeze can help protect you. It prevents new credit accounts from being opened in your name without your approval.
11) Add identity theft protection
Because this scam asks for your name, address, phone number, age, occupation and a copy of your passport or driver’s license, identity theft protection can help you spot trouble faster. A good service can monitor your credit files, alert you to new activity and help you recover if someone uses your information to open accounts or commit fraud in your name. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com
12) Report the scam
Mark the email as phishing in your inbox. This helps your email provider block similar messages and protects other people from falling into the same trap.
Join CyberGuy Live: Lock Down Your Phone in 30 Minutes (Saturday, June 13, 10 am ET)
Your phone holds your email, passwords, photos, banking apps and personal data. In this free, live online class, Kurt the CyberGuy will walk you step by step through simple phone security fixes you can do in real time. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Register here: CyberGuyLive.com
Kurt’s key takeaways
This email tries hard to look official. It uses a real organization, a real name and a convincing story. Still, the cracks show up quickly once you slow down. A Gmail reply address, a massive payout, a vague greeting and a request for identity documents all point in the same direction. Scams like this rely on one thing: getting you to act before you think. Take a second look, and the whole thing falls apart.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
If a message promises millions and asks for your personal information, would you pause long enough to question it, or would the urgency pull you in? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Blue Origin explosion is a major setback for NASA’s Moon plans and Amazon’s Starlink competitor
While Blue Origin investigates the root cause behind last night’s spectacular explosion of its New Glenn rocket, it’s already clear that this will be a major setback for NASA’s Moon base plans and Amazon’s fledgling Leo space internet constellation.
The incident occurred at about 9pm at Blue Origin’s Florida launch site during a hot-fire test, where seven engines in the booster stage are lit while keeping the 322-foot-tall rocket fixed to the launchpad. The explosion and ensuing fireball severely damaged the only launchpad Blue Origin has for its New Glenn rocket.
“It’s too early to know the root cause but we’re already working to find it,” wrote Blue Origin boss Jeff Bezos on X. “Very rough day, but we’ll rebuild whatever needs rebuilding and get back to flying. It’s worth it.”
According to sources speaking to Ars Technica, the transporter-erector and one of the lightning towers at LC-36A may not be salvageable. “New Glenn almost certainly will not launch again in 2026, and frankly a launch during the first half of 2027 would be heroic given the launch site concerns,” writes Eric Berger, senior space editor at Ars Technica.
Such a delay would affect NASA’s Moon base plans. NASA announced on Tuesday that New Glenn would deliver a robotic lunar lander as soon as fall 2026. In 2027, Blue Origin is also scheduled to participate in the upcoming Artemis III mission, which will see astronauts docking their Orion capsule with lunar landers developed by SpaceX and Blue Origin.
“Spaceflight is unforgiving, and developing new heavy-lift launch capability is extraordinarily difficult,” said NASA administrator Jared Isaacman on X. “We will work with our partners to support a thorough investigation of this anomaly, assess near-term mission impacts, and get back to launching rockets.”
The New Glenn rocket that exploded Thursday night was being prepped to carry 48 Amazon Leo satellites — the largest batch ever slated for a single launch — into low-Earth orbit on an upcoming mission. The satellites were not onboard.
To date Amazon has launched just over 300 of the 1,618 Leo satellites the FCC requires by July 30, 2026. Amazon has applied for an extension to keep its license.
Amazon had been counting on New Glenn’s massive payload capacity and reusable boosters to accelerate a launch schedule that is already behind. Without its primary workhorse, Amazon will be forced to rely more heavily on secondary providers like United Launch Alliance (ULA) and Arianespace — and its chief rival, SpaceX.
“Sorry to see this,” wrote fellow billionaire spaceman Elon Musk on X. “I hope you recover quickly.”
-
Utah2 minutes agoVideo: Utah startup employs those right out of prison and celebrates new milestone – KSLTV.com
-
Vermont8 minutes agoWith two major vacancies, who will lead the Vermont House and Senate? – VTDigger
-
Virginia14 minutes agoNetflix casting Central Virginia singles for “Love on the Spectrum” after Danville man joins show
-
Washington20 minutes agoAs an AI tech-hub, Washington must lead with conscience
-
Wisconsin26 minutes ago
Wisconsin National Guard troops return after yearlong deployment in Middle East
-
West Virginia32 minutes agoWheeling launches West Virginia’s first recovery housing program for young adults
-
Wyoming38 minutes ago
Critics oppose Wyoming hydroelectric project, pointing to climate-driven drought crisis
-
Crypto44 minutes agoStablecoin Settlement Is Here, but Seamless Off-Chain Money Movement Is Not | PYMNTS.com