Site icon BW Security World

Over-retention Scandal Exposes Millions Of Govt. IDs & Facial Biometrics

3d render of an internet security badge

The scale of a data breach affecting Discord users appears significantly worse than initially admitted

The security failures centre on data used for manual age verification, which a third-party vendor handling customer support for Discord—identified as Zendesk by some reports—was processing. The breach revealed that the company was holding copies of sensitive material, including government-issued IDs and facial photos, far beyond any regulatory requirement for age assurance laws worldwide.

The practice amounts to a clear case of over-retention, drastically increasing the liability for users whose biometric and identification details are now potentially in the hands of malicious actors. While Discord stated it is working with law enforcement and external security experts, the figures remain fiercely disputed.

Contradictions & Damage Control

Hackers have reportedly claimed to hold data for up to 5.5 million users, according to analysis by Bleeping Computer. Discord, however, has sought to minimise the scope of the catastrophe, stating: “Of the accounts impacted globally, we have identified approximately 70,000 users that may have had government-ID photos exposed, which our vendor used to review age-related appeals.”

The third-party service provider, Zendesk, has flatly denied involvement, asserting that its systems were not breached. This corporate pushback leaves the security failure in a murky jurisdictional dispute, but does not alter the fact that highly sensitive PII was improperly stored.

Widening Net Of Age Assurance

The breach throws a harsh light on the growing global demand for age verification, particularly as major platforms move to comply with new legislation, such as the UK’s Online Safety Act.

In a related development, Microsoft is preparing to roll out mandatory age verification for UK Xbox users who wish to access social features like text and voice chat.

Microsoft, which has been developing biometric facial age estimation technology for over a decade, offers users multiple options for age assurance: facial estimation, mobile provider checks, or submitting a government ID. Crucially, the tech giant emphasises that all data is encrypted and handled with rigorous protocols, a pointed contrast to the security lapse that has engulfed Discord and its partner.

The Discord incident serves as a stark warning to other platforms currently stockpiling user IDs—that the rush to compliance must be matched by equally robust security policies that adhere to the principle of data minimisation.

Exit mobile version