A massive cyberattack on Double Counter exposed the personal data of approximately 28 million Discord accounts. The attacker stole users’ IP addresses, usernames, and email addresses, took control of the security bot, and exploited access to the payment system to carry out fraudulent transactions.
Double Counter, a company that provides Discord servers with user verification tools and protection against fake accounts, confirmed a major breach of its infrastructure on October 4, 2026. The attacker remained inside the company’s cloud environment for nearly six hours, copying approximately 12 GB of data and sending invitations to their own Discord server through the official security bot. According to Double Counter’s official report, the attacker’s activity lasted 5 hours and 51 minutes, from 12:03 to 17:54 UTC. The company stated that the attack had been stopped and its services were restored later that same day.
The attacker’s primary target was Double Counter’s database, which stored information used to verify server members and detect alternative accounts. As a result of the attack, data associated with approximately 28 million accounts is considered potentially compromised.
The information that may have been exposed includes:
Discord IDs and usernames associated with approximately 28 million accounts.
IP addresses and approximate geolocation data of 27 million users, including country, region, city, postal code, and internet service provider.
User-Agent hashes associated with approximately 25 million accounts, used to identify alternative profiles.
Approximately 1 million email addresses associated with users and customers of the company’s services.
In addition, the system contained approximately 15 million VPN verification records, including IP addresses and browser information. However, Double Counter clarified that the attacker did not copy these records. According to the company, the attacker completely copied a table containing approximately 5.4 million IP records used to detect alternative accounts. Another table containing data on 21.7 million verified users was copied by approximately 20%. Since it is impossible to determine exactly which records were stolen, the company decided to treat the entire affected category of information as potentially compromised.
Meanwhile, a separate backup database containing information on approximately 58 million users remained untouched because it was stored outside the compromised infrastructure. The behavioral data database was also unaffected. Discord passwords were not exposed, as Double Counter does not collect or store them. Payment card details were also not present in the compromised database. Nevertheless, combining usernames, IP addresses, and geolocation data could help attackers link accounts together, track users across different communities, and carry out targeted phishing attacks.
According to Double Counter’s investigation, the initial entry point was an outdated server from the company’s previous infrastructure, hosted by OVH. Although the server was no longer used for the main service, it remained accessible from the internet. On October 3, the attacker began probing the server from various VPN addresses, testing user accounts and searching for weaknesses. Eventually, the attacker exploited a vulnerability in Metabase, an analytics tool that was still running on the old server.
The flaw allowed the attacker to forge an administrative session, gain access to the system, and discover credentials needed to enter Double Counter’s cloud infrastructure. These included a service account key with administrative privileges and a saved command-line session belonging to one of the administrators. The attacker did not create any new user accounts. Instead, they used existing legitimate credentials, making their activity initially harder to distinguish from normal administrative operations. On October 4 at 12:03 UTC, the attacker first used the stolen key to access the cloud environment. A few minutes later, they added their own SSH key and subsequently created a database export in cloud storage. However, this initial export was never downloaded.
After infiltrating the cloud infrastructure, the attacker gained access to the container running the Double Counter bot and stole its Discord token. This effectively allowed the attacker to control the bot and perform actions on its behalf. The attacker initially used this access to grant their own account administrator privileges on Double Counter’s support server, along with approximately 15 additional roles. When moderators banned the account, the attacker was able to reverse the ban themselves.
At approximately 13:30 UTC, the compromised bot began posting invitations to the attacker’s Discord server across roughly 50 large communities that relied on Double Counter for protection against fake accounts. One of the largest targets was the Steal a Brainrot server. The messages appeared to come from Double Counter itself, meaning users could mistake them for official communications. The invitations were sent directly through Discord, bypassing the company’s own infrastructure.
“Messages sent using the stolen token went directly to Discord without passing through our systems. Therefore, we identified affected servers based on reports we received and the bot’s own message history,” Double Counter representatives explained.
Most of the malicious invitations have since been removed by company employees or moderators of the affected servers.
The Double Counter team first attempted to stop the attack at 13:39 UTC by revoking the bot’s token. The bot temporarily stopped working, and the attacker lost the ability to control it. However, after a new token was issued at approximately 14:45 UTC, the hacker regained access to it just two minutes later through the compromised cloud environment.
Later, the attacker deleted the backups they had created, changed the database administrator’s password, and temporarily blocked legitimate services from accessing the database. Between 15:09 and 15:34 UTC, the hacker copied available database tables and managed to extract approximately 12 GB of information. Even after the primary access key was revoked, the attacker continued the operation using a saved administrative session previously discovered on the old server. The company finally stopped the attacker’s activity at around 17:55 UTC by revoking all sessions associated with the compromised administrator account.
During the attack, the hacker gained access not only to databases and Discord tokens but also to a Stripe payment key used by Atis, a separate product operated by Tellter. Using the stolen key, the attacker carried out a series of fraudulent transactions. The hacker initially made payments of $1, $10, $100, and $1,000, gradually increasing the amounts. In total, $7,316 was charged to the company’s corporate card.
The attacker also made two additional transactions of $3 and $15 using payment cards belonging to Atis customers. Both affected customers received full refunds. Overall, the fraudulent transactions involved three bank cards. Double Counter emphasized that the card numbers themselves were not stolen. Instead, the attacker processed payments through the compromised payment account without obtaining the actual card details. The payment keys were revoked at 17:14 UTC, after which the affected accounts were secured. The payment system handling subscriptions for Double Counter and Doogle was not affected.
After stopping the attack, the company conducted an extensive infrastructure security review, replaced compromised credentials, and closed the identified entry points. In particular, Double Counter shut down the old OVH server, removed the attacker’s SSH key, rotated Discord tokens, changed database passwords, and moved some services to a private cloud network without direct internet access.
The company also examined 14 cloud projects for hidden access mechanisms. According to the audit results, the attacker had not left behind additional keys, user accounts, scheduled tasks, or modified containers. Double Counter fully restored its services on October 4 at 19:19 UTC. Since then, the company has strengthened its monitoring of cloud infrastructure changes and tightened controls over the use of secret keys.
Double Counter also reported that it notified France’s data protection authority, CNIL, about the incident on October 5. The company has engaged lawyers to pursue those responsible for the attack in France and the United States and is preparing a criminal complaint.
Double Counter recommends that server administrators review messages posted by the bot on October 4 between 12:00 and 16:30 UTC. Any unexpected invitations to other Discord communities should be deleted. Administrators should also review their server’s audit log for that period. Regular Discord users do not need to change their passwords because of this incident, as their passwords were not compromised. However, the company advises users to avoid suspicious invitations, even when they appear to come from a familiar security bot.
Users who completed verification between 13:39 and 14:49 UTC but did not receive the appropriate server role are advised to repeat the verification process. Doogle users, advertisers, and API customers whose email addresses were exposed should be particularly cautious about phishing messages.
The Double Counter incident demonstrates that attackers do not necessarily need to compromise Discord itself to cause a massive data breach. Gaining access to a third-party service trusted by millions of users can be enough. In this case, an outdated server and an unpatched vulnerability became the starting point for an attack that put the personal data of approximately 28 million accounts at risk.