Double Counter Discord Bot Breach Exposes 28 Million User Records
On October 4, 2026, Double Counter, a security bot for Discord, disclosed a breach after attackers infiltrated its cloud infrastructure, exfiltrating 12 GB of database records and hijacking its bot token to spam unwanted invitations across 50 large Discord servers. The incident was contained by 19:19 the same day, with investigators confirming no backdoors remained in the 14 audited cloud projects.
The attack originated from an old OVH server part of Double Counter’s former hosting setup that still hosted a publicly accessible Metabase analytics tool. Exploiting a flaw, the attacker forged an admin session, gaining access to stored credentials, including a cloud service-account key with admin rights and a saved command-line session. This allowed them to pivot into production systems undetected, as their activity mimicked legitimate user behavior.
By 12:03, the attacker had added an SSH key, exported a database to a storage bucket, and accessed a bot container, exposing the Discord token. Though staff revoked the token at 13:39, the attacker quickly obtained the replacement, demonstrating the limitations of rotating a single secret while the underlying system remained compromised. They later changed the database admin password and exfiltrated records between 15:09 and 15:34, leveraging the stolen admin session even after the service-account key was revoked. Access was finally terminated at 17:55 after all compromised sessions were invalidated.
The breach exposed 28 million Discord IDs and usernames, 27 million IP-address and location records, 25 million user-agent hashes, and 1 million unique email addresses though these datasets overlap, preventing an exact victim count. Have I Been Pwned later identified 275,000 unique emails in publicly leaked data, a subset of the full exposure. Notably, Discord passwords and payment card details were not compromised, and 58 million users in cold storage remained unaffected. However, a stolen Stripe key enabled $7,316 in fraudulent charges on a company card, with two affected customers refunded.
In response, Double Counter shut down the old server, revoked all compromised credentials, deleted exposed webhooks, and migrated databases behind private networking. The bot now uses dedicated secret storage, with enhanced access logging and continuous monitoring to prevent future incidents. While the breach stemmed from legacy infrastructure, it underscores the risks of overlooked attack surfaces in cloud environments.
Source: https://cybersecuritynews.com/discord-users-data-exposed/
Double Counter TPRM report: https://www.rankiteo.com/company/tradedoubler
"id": "tra1791397442",
"linkid": "tradedoubler",
"type": "Breach",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '28 million Discord users '
'(estimated)',
'industry': 'Cybersecurity, SaaS',
'name': 'Double Counter',
'type': 'Security Bot for Discord'}],
'attack_vector': 'Exploited vulnerable Metabase analytics tool on legacy '
'server',
'customer_advisories': 'Public disclosure of breach, refunds for affected '
'customers',
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': '28 million (overlapping '
'datasets)',
'personally_identifiable_information': ['Discord IDs',
'Usernames',
'IP addresses',
'Location records',
'Email addresses'],
'sensitivity_of_data': 'High (PII, including 275,000 unique '
'emails)',
'type_of_data_compromised': ['Discord IDs',
'Usernames',
'IP addresses',
'Location records',
'User-agent hashes',
'Email addresses']},
'date_detected': '2026-10-04T12:03:00',
'date_publicly_disclosed': '2026-10-04',
'date_resolved': '2026-10-04T19:19:00',
'description': 'On October 4, 2026, Double Counter, a security bot for '
'Discord, disclosed a breach after attackers infiltrated its '
'cloud infrastructure, exfiltrating 12 GB of database records '
'and hijacking its bot token to spam unwanted invitations '
'across 50 large Discord servers. The incident was contained '
'by 19:19 the same day, with investigators confirming no '
'backdoors remained in the 14 audited cloud projects.',
'impact': {'brand_reputation_impact': 'Exposure of 28 million user records, '
'spam distribution via bot',
'customer_complaints': 'Two affected customers refunded',
'data_compromised': '12 GB of database records',
'financial_loss': '$7,316 in fraudulent Stripe charges',
'identity_theft_risk': 'High (Discord IDs, usernames, IP/location '
'records, email addresses)',
'operational_impact': 'Bot token hijacked to spam Discord servers, '
'temporary loss of control over bot '
'functionality',
'payment_information_risk': 'None (no payment card details '
'compromised)',
'systems_affected': ['Cloud infrastructure',
'Discord bot token',
'Metabase analytics tool',
'Stripe key']},
'initial_access_broker': {'entry_point': 'Old OVH server hosting vulnerable '
'Metabase analytics tool',
'high_value_targets': ['Cloud service-account key',
'Discord bot token',
'Stripe key']},
'investigation_status': 'Completed',
'lessons_learned': 'Risks of overlooked legacy infrastructure in cloud '
'environments, limitations of rotating single secrets, '
'importance of comprehensive access logging and '
'monitoring.',
'motivation': 'Data exfiltration, financial fraud, spam distribution',
'post_incident_analysis': {'corrective_actions': ['Decommissioned old server',
'Revoked all compromised '
'credentials',
'Migrated databases to '
'private networking',
'Implemented dedicated '
'secret storage',
'Enhanced monitoring and '
'logging'],
'root_causes': ['Legacy infrastructure with '
'vulnerable Metabase tool',
'Publicly accessible server',
'Stored credentials in accessible '
'locations',
'Insufficient access logging']},
'ransomware': {'data_exfiltration': True},
'recommendations': ['Audit and decommission legacy systems',
'Implement dedicated secret storage',
'Enforce private networking for databases',
'Enhance continuous monitoring',
'Rotate all credentials comprehensively during incidents'],
'references': [{'source': 'Double Counter Incident Report'},
{'source': 'Have I Been Pwned'}],
'response': {'containment_measures': ['Revoked compromised credentials',
'Invalidated all compromised sessions',
'Shut down old OVH server',
'Deleted exposed webhooks'],
'enhanced_monitoring': True,
'incident_response_plan_activated': True,
'network_segmentation': True,
'recovery_measures': ['Restored bot functionality',
'Refunded affected customers'],
'remediation_measures': ['Migrated databases behind private '
'networking',
'Implemented dedicated secret storage',
'Enhanced access logging',
'Continuous monitoring']},
'title': 'Double Counter Discord Bot Breach Exposes 28 Million User Records',
'type': 'Data Breach',
'vulnerability_exploited': 'Forged admin session via Metabase flaw, stolen '
'cloud service-account key with admin rights'}