Double Counter Discord Bot Breach Exposes Millions of Records
Double Counter’s October 4 breach exposed about 28 million Discord IDs, 27 million IP records, and roughly one million emails.
Tellter SAS said an attacker breached its Discord security bot Double Counter on October 4, 2026, via a retired or unused OVH server that still exposed Metabase, then reused cloud administrator credentials. The intruder copied about 12 GB and exposed roughly 28 million Discord IDs and usernames, about 27 million IP and location records, user-agent hashes for about 25 million accounts, and roughly one million emails; one report puts the intrusion at 5 hours 51 minutes. A stolen bot token was used to post invitations on about 50 large servers, and one source says a rotated bot token was retaken within two minutes. Sources disagree on the initial step, with one describing a forged administrator session and the other a Metabase flaw. Passwords and stored card numbers were not taken—one source says passwords were never stored—while a stolen Stripe key, linked by one report to the separate product Atis, caused $7,316 in fraudulent charges. Discord itself was not confirmed compromised. Tellter revoked sessions and credentials, shut down the legacy server, and notified France’s CNIL; cold storage (about 58 million users in one account) and VPN logs were not copied, and the provider says the attack is contained.
- Tellter SAS said an attacker breached Discord security bot Double Counter on October 4, 2026, through a retired or unused OVH server that still exposed Metabase, then reused cloud administrator credentials.
- The intruder copied about 12 GB, exposing roughly 28 million Discord IDs and usernames, about 27 million IP and location records, user-agent hashes for about 25 million accounts, and roughly one million emails.
- One report says the attacker was active for 5 hours 51 minutes, posted invitations on about 50 large servers with a stolen bot token, and retook a rotated bot token within two minutes.
- Passwords and stored card numbers were not taken; one source says passwords were never stored.
- A stolen Stripe key, tied by one report to the separate product Atis, caused $7,316 in fraudulent charges.
- Sources differ on whether access began by forging an administrator session or exploiting a Metabase flaw.
- Cold storage (about 58 million users in one account) and VPN logs were not copied; sessions and credentials were revoked, the legacy server was shut down, and France’s CNIL was notified.
- Discord itself was not confirmed compromised, and the provider says the attack is contained.
Coverage timelineoldest first · each row is one article
- · 1d agoDiscord Users’ Data Exposed in Security Bot Double Counter Security Breach
Cyber Security News· 82
A Double Counter Discord bot breach exposed tens of millions of IDs and IPs and about one million emails.
- · 14h agoDiscord Security Bot Double Counter Hacked, Exposing Data of Millions of Users
GBHackers· 83
Double Counter’s Discord bot breach exposed identifiers, IPs, and emails tied to tens of millions of accounts.