Discord Users’ Data Exposed in Security Bot Double Counter Security Breach
A Double Counter Discord bot breach exposed tens of millions of IDs and IPs and about one million emails.
Double Counter, a Discord security bot, said an attacker breached its cloud on October 4, 2026, through an unused OVH server that still exposed Metabase. The attacker forged an administrator session, reused cloud credentials, stole the bot token, and posted invitations on about 50 large servers before copying roughly 12 GB of records. Double Counter treats about 28 million Discord IDs and usernames, 27 million IP and location records, user-agent hashes for about 25 million accounts, and roughly one million emails as exposed. Discord passwords and stored card numbers were not taken; a stolen Stripe key caused $7,316 in fraudulent charges. Discord itself was not confirmed compromised, and the provider says the attack is contained.
- Attacker entered via an old OVH server still exposing Metabase.
- About 28 million Discord IDs and 27 million IP records counted exposed.
- Roughly one million emails copied; passwords and card numbers were not.
- Stolen bot token sent invites; a Stripe key caused $7,316 in fraud.
- Sessions were revoked; cold storage for about 58 million users was untouched.
Full article607 words · extracted from cybersecuritynews.com · click to collapse
Double Counter, a Discord security bot, has disclosed a breach that exposed user data after an attacker broke into its cloud systems on October 4, 2026. Attackers copied about 12 GB of database records, and the stolen bot token was used to post unwanted invitations across roughly 50 large Discord servers.
According to Double Counter’s official incident report, the attack is contained and service was restored at 19:19. Investigators audited 14 cloud projects and found no backdoors. The breach involved the bot provider’s infrastructure, not a confirmed compromise of Discord itself.
Double Counter Security Breach
The attacker entered through an old OVH server from Double Counter’s previous hosting setup. Although disconnected from the live service, it still ran a publicly reachable Metabase analytics tool. A flaw let the attacker forge an administrator session and access credentials stored on the host.
Those secrets included a cloud service-account key with administrator rights and an administrator’s saved command-line session. This turned an unused server into a bridge to production systems. Because the attacker reused valid identities rather than creating accounts, their activity initially looked less suspicious.
Cybersecurity News previously reported on an actively exploited Metabase flaw. However, Double Counter’s disclosure does not name a CVE or advisory, so linking this incident to that specific vulnerability would be premature.
Cloud access began at 12:03. The attacker added an SSH key, exported a database into a storage bucket, and opened a shell inside a bot container. That shell exposed the Discord token. The attacker never downloaded the first database export.
The stolen token let the attacker grant their account administrator rights on the support server, reverse a staff ban, and send invitations under Double Counter’s identity.
Staff invalidated the token at 13:39, but restoring the bot with a replacement did not remove the attacker’s cloud access. They read the new token within two minutes. This shows why changing one secret cannot contain an attack while the system holding that secret remains compromised.
The attacker later changed the database administrator password and copied records between 15:09 and 15:34. Revoking the service-account key also proved insufficient: they switched to the stolen administrator session. Access ended only after they revoked those sessions around 17:55.
Double Counter treats approximately 28 million Discord IDs and usernames and 27 million IP-address and location records as exposed. It also reports copied user-agent hashes covering about 25 million accounts and roughly one million unique email addresses. These groups overlap, so adding them would overstate the number of victims.
Only part of the larger IP-address table was copied. Because investigators cannot identify which rows were left out, they count the entire table as exposed. Have I Been Pwned lists roughly 275,000 unique email addresses in publicly released data, a smaller dataset than the provider’s reported exposure.
Discord passwords and stored card numbers were not exposed. Cold storage covering roughly 58 million users remained unaffected. A stolen Stripe key enabled $7,316 in fraudulent charges against a company card on the separate Atis account. Two customer charges were refunded.
Responders shut down the old server, revoked cloud access, rotated credentials, deleted exposed webhooks, and moved databases behind private networking. The token now uses dedicated secret storage. Secret-access logging and continuous monitoring now support the restored service.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.