# The Discord Leak is Bigger Than Expected - Threat Wire

Source: https://www.youtube.com/watch?v=7rg46Z6ZwCc
Recap page: https://rapidrecap.app/video/7rg46Z6ZwCc
Generated: 2025-10-15T17:32:43.796+00:00

---
## Quick Overview

The apparent size of the Discord data leak, which compromised a third-party customer service provider, was significantly larger than initially reported, ultimately exposing government IDs and impacting around 70,000 users, while concurrently, a new study revealed that large language model (LLM) data poisoning attacks are surprisingly easy to execute, requiring only a small, fixed percentage of malicious training data to backdoor models.

**Key Points:**
- The Discord security incident, involving a third-party customer service provider, compromised data affecting approximately 70,000 users, including government IDs.
- Discord published an update on October 3rd, 2025, confirming the breach originated from the compromised third-party vendor.
- The attacker demanded a financial ransom, but Discord revoked the vendor's access and engaged law enforcement and a computer forensics firm.
- A new paper by researchers at UK AI Security Institute and the Alan Turing Institute demonstrated that LLM poisoning is easier than expected.
- The study found that poisoning attacks require a near-constant number of malicious documents regardless of the LLM's parameter size (tested up to 138 billion parameters).
- Only 250 malicious documents (roughly 420k tokens, representing 0.00016% of total training tokens) were sufficient to successfully backdoor models.
- BreachForums, a data leak extortion site used by the ShinyHunters group, was seized by the FBI and French law enforcement on October 7th, 2025.

![Screenshot at 0:15: The video displays the Discord security incident announcement screen detailing the 'Update on a Security Incident Involving Third-Party Customer Service', setting the context for the expanded scope of the leak.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-00-15.png)

**Context:** This episode of Threat Wire covers two significant cybersecurity events: the escalation of a data breach at Discord involving a third-party vendor, and alarming new research detailing the ease of data poisoning attacks against large language models (LLMs). The Discord situation highlights risks associated with third-party access, while the LLM research underscores a growing vulnerability in AI model training data.

## Detailed Analysis

The video first addresses the Discord data leak, revealing that the initial reports understated the impact. The breach occurred via a third-party customer service provider, leading to the exposure of approximately 70,000 users' data, including government IDs. Discord took immediate steps upon discovery on September 20th, 2025, by revoking access, launching an internal investigation, hiring a forensics firm, and involving law enforcement. The attackers had demanded a ransom, but their access was revoked. Subsequently, the host discusses a new paper detailing how easy it is to poison Large Language Models (LLMs). The research, conducted by UK AI Security Institute and the Alan Turing Institute, found that poisoning attacks require a nearly constant number of malicious documents, irrespective of the model size, even for models up to 138 billion parameters. Just 250 malicious documents, equating to only 0.00016% of total training tokens, were enough to successfully backdoor the models, causing them to generate incoherent responses when prompted with a specific trigger word. Finally, the video reports that BreachForums, a notorious hacking forum used by the ShinyHunters group for data leak extortion following the Salesforce theft, was seized on October 7th, 2025, through a joint operation between the FBI and French law enforcement, although the site briefly came back online before being fully controlled by authorities.

### Discord Data Leak Escalation

- Compromised third-party customer service provider
- Affected around 70,000 users, including government IDs
- Discord responded by revoking access and launching investigations

### LLM Data Poisoning Research

- Study showed poisoning attacks require a near-constant number of documents regardless of model size
- Models up to 138B parameters were tested
- Only 250 malicious documents (0.00016% of tokens) caused backdoors

### BreachForums Takedown

- FBI and French law enforcement seized BreachForums on October 7, 2025
- Site was used by ShinyHunters for Salesforce extortion
- The site briefly returned before being fully seized

![Screenshot at 0:04: Satellite map overlay used as a background graphic during the introduction.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-00-04.png)
![Screenshot at 0:07: Title card graphic for the segment 'THREAT WIRE' displayed.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-00-07.png)
![Screenshot at 0:10: Text overlay stating the main topic: 'Discord Leak is Bigger Than Expected'.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-00-10.png)
![Screenshot at 0:15: Screenshot of Discord's official security update page regarding the third-party customer service incident.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-00-15.png)
![Screenshot at 0:53: Quote displayed over the satellite map background summarizing Discord's immediate response steps to the attack.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-00-53.png)
![Screenshot at 1:21: Text overlay indicating the second topic: 'LLM Poisoning Is Actually Easy'.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-01-21.png)
![Screenshot at 1:56: Visual slide from the research paper stating: 'A small number of samples can poison LLMs of any size'.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-01-56.png)
![Screenshot at 3:25: News article screenshot showing the FBI seizure of BreachForums domains, featuring seals from the DOJ, FBI, and others.](https://ss.rapidrecap.app/screens/7rg46Z6ZwCc/00-03-25.png)
