Take‑Two Subpoenas Microsoft & Discord for User Data, Threatening Exposure of Thousands of Discord Users
What Happened – Take‑Two Interactive served subpoenas to Microsoft and Discord on Aug 20, demanding IP addresses, phone numbers, linked Google/Xbox accounts, OneDrive contents, MachineGuid values and Microsoft device IDs for members of three GTA‑related Discord servers dating back to June 1. The request could hand over identifying data for hundreds‑to‑thousands of users who have no proven link to the GTA 6 leak.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the risk of third‑party data requests that can surface personal information, testing the Privacy principle of SOC 2 and GDPR/CCPA obligations.
- Highlights the need for documented data‑minimization, consent, and DSAR (Data Subject Access Request) processes that can be produced as audit evidence.
- Aligns with Verisq’s CookiePLUS Privacy capability, which helps organizations manage consent, track data flows, and generate compliance reports for privacy‑focused audits.
Who Is Affected – Gaming & entertainment companies, online community platforms, and any organization that integrates Discord or Microsoft services for user interaction.
Recommended Actions
- Conduct a data‑flow mapping exercise for all Discord‑integrated services and identify what personal data is stored or shared.
- Verify that consent mechanisms (e.g., Discord server rules, in‑app notices) meet GDPR/CCPA standards and are documented in your privacy policy.
- Update DSAR procedures to include rapid response to third‑party subpoenas and ensure you can produce audit‑ready evidence of lawful basis for data sharing.
Source: Malwarebytes Labs
Technical Notes – The subpoena targets device identifiers (MachineGuid, Microsoft device ID) and linked account data. No vulnerability or exploit is disclosed; the risk stems from legal compulsion to disclose data held by third‑party platforms. Source: same as above