Opens in a new tab

Double Counter Breach Exposes 28 Million Accounts

Discord breach reportedly exposes 28 million user accounts

The Double Counter breach has potentially exposed data associated with approximately 28 million Discord accounts. However, the compromised service was a third-party verification provider, not Discord itself.

The incident began on 4 October 2026 after an attacker gained access through a self-hosted analytics system on a retired server. The attacker copied data, stole a Discord bot token and used a payment key to make fraudulent charges.

What happened in the Double Counter breach?

Double Counter is a Discord verification and anti-alt service operated by Tellter SAS. It is used by hundreds of thousands of Discord servers to identify alternative accounts and perform checks on people joining online communities.

On 4 October 2026, an attacker compromised a legacy server hosted by OVH that was still running a self-hosted Metabase analytics instance. Public reporting says a Metabase vulnerability allowed the attacker to forge an administrator session and obtain privileged access. The specific Metabase version and vulnerability identifier have not been disclosed.

The retired server contained a cloud service-account key with administrator permissions and a saved administrative command-line session. These credentials enabled the attacker to move from the old server into Double Counter’s active cloud environment.

During an intrusion lasting just under six hours, the attacker exported a database to a newly created storage bucket and copied approximately 12 GB of tables. The attacker also added an SSH key, opened a shell inside a running bot container and retrieved Double Counter’s Discord bot token.

The stolen token was then used to post invitation links to an attacker-controlled server across roughly 50 large Discord communities. An initial attempt to rotate the token was ineffective because the attacker still had access to the underlying infrastructure and quickly obtained the replacement.

Double Counter breach timeline

Initial probing and access

According to the incident timeline, probing of the legacy Metabase server began at 04:37 UTC on 3 October 2026. The activity came from rotating VPN addresses.

The main intrusion occurred on 4 October. After obtaining administrator-level access to Metabase, the attacker pivoted into Double Counter’s cloud environment at 12:03 UTC. At 12:26, the attacker accessed the Discord bot token held within a running container.

Data theft and service disruption

At 15:09 UTC, the attacker changed the database administrator password. By approximately 15:34, database tables totalling around 12 GB had been copied. Double Counter continued restoration and containment work during the evening.

The attacker also obtained a Stripe payment key associated with a separate Tellter product. It was used to place fraudulent charges totalling $7,316 on a company card. Two small charges were made against customers, but these were refunded.

Disclosure and public data release

Double Counter publicly disclosed the incident on 5 October 2026 and notified France’s data protection authority, CNIL. The company said it had rotated credentials, placed bot tokens and webhooks in a dedicated secrets store, and was continuing its investigation.

On 7 October, a dataset containing 274,922 unique email addresses and associated Discord usernames was added to Have I Been Pwned. Mozilla Monitor also reflected the breach listing. This confirmed that information from the Double Counter breach had been released publicly.

On 8 October, further reporting consolidated the scale of data that Double Counter was treating as exposed. By then, Discord had confirmed that its own platform had not been breached and said new installations of the Double Counter application had been disabled while it assessed the incident.

What data was potentially exposed?

The figure of 28 million accounts requires careful interpretation. It represents the population of Discord user records that Double Counter says it is treating as exposed within its environment, rather than the number of records confirmed in the public data release.

The potentially affected information includes:

  • Approximately 28 million Discord user IDs and usernames.
  • About 27 million IP addresses, with coarse geolocation and internet service provider information.
  • Around 25 million user-agent hashes.
  • Roughly 1 million email addresses.
  • Approximately 15 million VPN detection records.

The smaller publicly released corpus contained 274,922 unique email addresses with Discord usernames. It also reportedly included a limited set of paying subscriber details, such as names, countries and postcodes.

These numbers describe different datasets. The larger total covers records potentially accessed during the Double Counter breach, while the smaller figure covers unique email addresses confirmed in the published corpus. Double Counter states that Discord account passwords and stored payment card numbers were not exposed.

How the attacker moved through the environment

The initial weakness was not reported as a flaw in Discord. The entry point was an exposed Metabase deployment left running on retired infrastructure. Once the attacker obtained administrative access, credentials retained on that system provided a route into current cloud resources.

This access allowed the intruder to create storage resources, export database contents and interact with production workloads. Changing the database administrator password also disrupted the provider’s control of its systems during the attack.

The theft of the bot token turned the incident from data access into active exploitation. Because Discord servers trusted the Double Counter bot, the compromised token could be used to publish malicious invitations through an apparently legitimate account. No credible public attribution for the attacker had been announced by 8 October 2026.

No vendor-published IP addresses, file hashes, domains or other technical indicators of compromise have been identified in public reporting. Detection therefore depends mainly on reviewing bot activity, unexpected invitations and authentication or infrastructure changes around the incident period.

Current exploitation status and user risk

The Double Counter breach has been exploited in the wild. The stolen bot token was actively misused across around 50 large communities, and a portion of the accessed personal information has been published.

The combination of email addresses, Discord usernames, server associations and network information could support convincing phishing attempts. Messages may refer to a community, verification process or account warning to encourage recipients to open a link or disclose credentials.

Discord’s decision to suspend new Double Counter installations limits further adoption while its assessment continues. Existing server owners should not interpret this as evidence that every Discord account or server was directly compromised.

What UK organisations should do now

Organisations using Discord should determine whether Double Counter is installed in any company-managed or community server. Administrators should review recent bot messages, permission changes and invitation links, particularly activity associated with the affected service.

  • Remove or restrict Double Counter until the organisation is satisfied with its security status.
  • Review every installed bot and limit its permissions to those strictly required.
  • Ask exposed users to check their email address through a recognised breach-notification service.
  • Warn staff and community managers about phishing messages referring to Discord verification or familiar servers.
  • Reset credentials where passwords were reused, and enable multi-factor authentication for Discord and associated email accounts.

The Double Counter breach demonstrates how a trusted integration can create exposure without the main platform being breached. The immediate priority is to identify affected servers, investigate suspicious bot activity and prepare users for targeted social engineering based on the published data.

Originally reported by Cybernews.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call