Discord Users’ Data Exposed in Security Bot Double Counter Security Breach
A Double Counter Discord bot breach exposed tens of millions of IDs and IPs and about one million emails.
Double Counter, a Discord security bot, said an attacker breached its cloud on October 4, 2026, through an unused OVH server that still exposed Metabase. The attacker forged an administrator session, reused cloud credentials, stole the bot token, and posted invitations on about 50 large servers before copying roughly 12 GB of records. Double Counter treats about 28 million Discord IDs and usernames, 27 million IP and location records, user-agent hashes for about 25 million accounts, and roughly one million emails as exposed. Discord passwords and stored card numbers were not taken; a stolen Stripe key caused $7,316 in fraudulent charges. Discord itself was not confirmed compromised, and the provider says the attack is contained.