News

Discord Double Counter Breach Exposes Emails, IDs, and Server Risks

Discord bot Double Counter breached: 275,000 email addresses exposed
Big Brain
Big Brain
Published
10/7/2026
Read Time
5 min

The Double Counter data breach exposed Discord usernames, emails, IDs, IP data, and payment-customer details. Here is what gaming communities and players should do now.

Discord bot Double Counter breached: 275,000 email addresses exposed

Image: en.softonic.com

A security bot became the attack surface

Double Counter, a third-party Discord security service used to protect servers from raids and alt accounts, has disclosed a breach that it describes as a “deliberate, multi-stage attack” on October 4, 2026. The immediate tension for gaming communities is simple: a tool installed to reduce account abuse became the source of a Discord breach affecting emails, Discord IDs, usernames, IP data, and some payment-customer records.

According to Double Counter’s incident report, as cited by GamesIndustry.biz and Rock Paper Shotgun, attackers exploited a vulnerability in a publicly accessible analytics tool on a legacy server and used that foothold to reach cloud credentials. GamesIndustry.biz reports that the attackers had access for just under six hours. Cybersecurity News, also citing Double Counter’s report, says the old server belonged to a previous hosting setup and still exposed a Metabase analytics tool, turning unused infrastructure into a path toward production systems.

Discord itself is not reported to have been directly compromised. Cybersecurity News states that the breach involved the bot provider’s infrastructure rather than a confirmed compromise of Discord. That distinction matters, but it does not make the exposure minor for server owners. Double Counter’s job is account verification and alt detection, which means the service can hold data that maps Discord identities to emails, IP addresses, coarse locations, user-agent information, and payment records. In a multiplayer community, those links are strategically valuable to moderators. They are also strategically valuable to attackers.

What data was exposed, and what was not

The largest confirmed exposure is broader than the publicly posted dataset. GamesIndustry.biz reports that Double Counter is treating Discord IDs and usernames for about 28 million accounts as exposed, along with IP addresses and coarse location data for about 27 million users. Cybersecurity News adds that Double Counter also reported user-agent hashes covering about 25 million accounts and roughly one million unique email addresses. Those groups overlap, so they should not be added together as if they represent separate victims.

Double Counter’s own estimate, reported by Rock Paper Shotgun, puts affected email addresses at around one million. Have I Been Pwned lists a smaller public corpus: 274.9k affected email addresses, added on October 7, 2026, with Discord usernames included in the published data. GamesIndustry.biz rounds that same public release to 274,900 email addresses and Discord usernames, while Rock Paper Shotgun and Softonic describe it as about 275,000. The difference is rounding, not a separate count.

Have I Been Pwned says the compromised data in the public corpus includes email addresses, geographic locations, names, and usernames. It also says a small number of records for paying subscribers processed through Stripe included names, countries, and postcodes. GamesIndustry.biz similarly reports that records for paying customers included names, countries, and postal codes.

There are important limits to the known exposure. Cybersecurity News reports that Discord passwords and stored card numbers were not exposed, and that cold storage covering roughly 58 million users remained unaffected. That does not erase the risk from a Discord email leak, but it changes the correct response. This is primarily an identity-correlation and phishing problem, not a confirmed password dump.

How the attack unfolded

The technical chain matters because it explains why a simple token reset was not enough. Cybersecurity News reports that the attacker entered through an old OVH server from Double Counter’s previous hosting setup. Although disconnected from the live service, it still hosted a public Metabase analytics tool. A flaw allowed the attacker to forge an administrator session and access credentials stored on the host.

Those secrets reportedly included a cloud service-account key with administrator rights and an administrator’s saved command-line session. Cybersecurity News says cloud access began at 12:03, after which the attacker added an SSH key, exported a database into a storage bucket, and opened a shell inside a bot container. That shell exposed the Discord bot token.

The stolen token had immediate community-facing consequences. GamesIndustry.biz reports that attackers used it to post malicious links in about 50 large Discord servers. Cybersecurity News says the token let the attacker grant their account administrator rights on Double Counter’s support server, reverse a staff ban, and send invitations under Double Counter’s identity.

Staff invalidated the first token at 13:39, according to Cybersecurity News, but the attacker still had cloud access and read the replacement token within two minutes. That is the key lesson for admins running large gaming communities: rotating one secret does not contain an incident while the system that stores or deploys that secret remains compromised. Cybersecurity News reports that the attacker later changed the database administrator password and copied records between 15:09 and 15:34. Access ended only after sessions were revoked around 17:55.

Double Counter said it disabled stolen credentials, rotated secrets, moved databases to private networks, and restored service on October 4, according to GamesIndustry.biz. The company notified France’s data protection authority, CNIL, on October 5. Cybersecurity News reports that investigators audited 14 cloud projects and found no backdoors.

Why gaming communities should care about IDs and IP data

For a typical player, a Discord ID can sound harmless because it is not a password. In moderation systems, however, it is a durable identifier that can connect a username history, server membership signals, bot checks, and ban-evasion decisions. When paired with an email address, IP address, coarse location, ISP data, or payment-customer details, it becomes useful for targeted scams and harassment.

Softonic reports that Double Counter is used in more than 600,000 Discord communities. That figure helps explain the scale of the concern for games, esports teams, guilds, modding hubs, raid groups, trading communities, and creator servers. A bot that sits at the gate of many servers can accumulate data across a wide community footprint, especially when its role is to detect alt accounts and raids.

Double Counter’s own purpose creates the dilemma. Server owners install tools like this because open Discord communities are vulnerable to spam raids, ban evasion, impersonation, and malicious mass joins. The operational value comes from correlation. The privacy risk comes from the same correlation. If the data is breached, attackers do not need Discord’s central systems to be compromised to build better phishing lists or identify which players, moderators, streamers, or guild leaders might be worth targeting.

Rock Paper Shotgun notes that Double Counter’s effectiveness and privacy practices have been debated by Discord users, and that the service had previously been accused of selling user data. The breach does not resolve those older debates, but it makes the cost side clearer. Community security tools should be evaluated like infrastructure, not like harmless server cosmetics.

What server owners should do now

Double Counter’s own advice, reported by GamesIndustry.biz, is that server administrators should delete suspicious Double Counter messages from October 4. That instruction is narrow, but it is the first practical step because the stolen bot token was used to post malicious links in roughly 50 large servers.

Admins should also treat this as a permissions audit moment. The source material confirms that a stolen bot token allowed malicious messages and server-level abuse under Double Counter’s identity. For any gaming community that relies on verification, anti-raid, ticketing, giveaway, or economy bots, the right question is whether each bot still needs the permissions it has. If a bot can post in announcement channels, mention everyone, manage roles, or access moderation logs, a token compromise can become a community-wide incident.

The forward-looking strategy is to reduce blast radius. Server owners should review bot roles, separate announcement permissions from moderation permissions where possible, check logs for unusual messages on October 4, and communicate clearly with members if their server received a suspicious Double Counter post. The sources do not report that all Double Counter-protected servers received malicious links, so admins should avoid claiming their communities were directly targeted unless their own logs show it.

There is also a vendor-management lesson. GamesIndustry.biz reports that the attackers exploited a publicly accessible analytics tool on a legacy server. Cybersecurity News says the server should have been retired but still contained live credentials. Community owners cannot audit a bot provider’s cloud estate, but they can decide how much access a third-party bot deserves and whether the bot’s security model matches the sensitivity of their server.

What players can do to reduce account risk

Double Counter said server members do not need to take action on their Discord accounts, according to GamesIndustry.biz. That statement should be read narrowly: the sources report no exposed Discord passwords and no direct compromise of Discord itself. It does not mean players should ignore the breach.

Have I Been Pwned lists the Double Counter breach with 274.9k affected email addresses in the publicly released dataset. Players can check whether their email appears there. If it does, they should expect more targeted phishing that references Discord, server verification, bans, appeals, giveaways, moderation, or account safety. A realistic attacker does not need a password if they can trick a player into entering one on a fake login page.

Because Discord passwords were not reported exposed, a blanket panic reset is less useful than focused hygiene. Players should make sure their Discord password is unique, enable two-factor authentication where available, and change passwords on any account where the same email-and-password combination was reused. Have I Been Pwned recommends changing affected passwords and enabling 2FA wherever supported, which is good general breach practice even though this incident is not reported as a password leak.

Players should also be cautious with old verification links or bot messages from October 4. If a server asks members to re-verify through an unfamiliar link, confirm it through a trusted moderator channel first. For players who stream, run guilds, manage esports scrims, or moderate large servers, the risk profile is higher because leaked identifiers can support impersonation, doxxing attempts, harassment, or targeted social engineering.

Discord’s broader trust problem remains unresolved

This breach arrives during a sensitive period for Discord’s privacy posture. GamesIndustry.biz notes that Discord has been trying to relaunch age verification after an earlier rollout drew privacy concerns. In February, Discord announced age verification would be required for all users starting in March, but GamesIndustry.biz reports that the rollout was postponed to the second half of 2026 after backlash. The company restarted verification efforts at the end of last month after introducing alternative methods that do not require video selfies or ID, according to the same outlet.

That context does not make Discord responsible for every third-party bot failure. The reported attack path runs through Double Counter’s infrastructure, not Discord’s core platform. Still, players experience Discord as one ecosystem. If a community’s required verification bot leaks email and IP data, the practical result is a Discord-shaped security problem for the people in that community.

For server owners, the meta has shifted. Anti-raid tooling remains necessary for large gaming spaces, but every bot that collects identity signals should now be treated as a risk tradeoff. The strongest communities will not be the ones with the most automated gates. They will be the ones that use fewer high-permission tools, document what each bot can access, keep incident announcements calm and specific, and teach members how to spot phishing before the next breach turns leaked data into account theft.

Share: