Cyber & AI intelligence
Wasteland.
Briefs indexed3041
Issues31
Published Mondays07:30 CT
▣ Breach DOUBLE-COUNTER-DIS 2026-10-07

Double Counter: Metabase Flaw Exposes Millions of Discord User Records

"Double Counter is a third-party anti-alt and anti-raid bot used by Discord server operators. It has confirmed a "deliberate, multi-stage attack" on October 4, 2026. The attacker got in through a forgotten legacy server…"

Double Counter is a third-party anti-alt and anti-raid bot used by Discord server operators. It has confirmed a "deliberate, multi-stage attack" on October 4, 2026. The attacker got in through a forgotten legacy server running a vulnerable self-hosted Metabase instance and copied about 12 GB from one of the company's databases. Figures for the exposure vary depending on what is being counted. The company's incident report, as relayed by several outlets, says about 1 million email records and roughly 25 million user-agent hashes were copied. It also says about 28 million Discord user IDs, usernames and IP records were "partially copied." Have I Been Pwned (HIBP) lists 274,922 unique email addresses and usernames in a data set that has already been published. Discord's own platform was not breached. The exposed data was held by the bot operator.

A note on sourcing: none of the eight sources available for this brief is a primary document. Double Counter's own incident report (INC-2026-10-04) is quoted here only through secondary coverage, so treat the figures below as reported, not independently verified.

What Happened

Reconstructed from coverage of Double Counter's incident report (AliasFleet, Abijita, TalkEsport and Massively Overpowered):

HookPhish's breach listing gives the date as "2024-10-04", which looks like an aggregation error. Every other source puts the incident in October 2026.

What Was Taken

Counts differ depending on whether a source means data the company says was copied or data that has been published:

Data type Reported volume Source
Discord user IDs and usernames ~28M, "partially copied" and treated as exposed Company report via S1, S6, S8
IP address plus coarse geolocation (country, region, city, postcode, ISP) ~27M records Company report via S6, S8
User-agent hashes (one-way hash of browser UA, city and country, used for alt detection) ~25M Company report via S1, S8
Email records copied ~1M (about 840k "Doogle" accounts and ~240k dashboard and customer contacts) Company report via S1, S3, S8
Emails and usernames in the public leak 274,922 unique HIBP via S2, S4, S7
Paying-subscriber records (name, country, postcode, processed via Stripe) "A small number" HIBP via S2, S5
Total data copied ~12 GB from one database S3, S8

The two email figures do not contradict each other. Roughly 1 million email records were copied, and about 275,000 of them have surfaced publicly so far. PC Guide reports that 25% of the published addresses were already in HIBP from earlier breaches. Reports say Discord passwords and full card numbers were not exposed (TalkEsport, Massively Overpowered).

The most sensitive part of the data set is the IP and geolocation table. As AliasFleet points out, those records belong to people who simply clicked a verification link to join a server, and most never signed up for Double Counter directly.

Why It Matters

The Attack Technique

Sources broadly agree on the intrusion chain:

  1. Initial access: A legacy OVH server was still publicly reachable after decommissioning and still ran a self-hosted Metabase instance. According to AliasFleet, the company said the server was "no longer in use and no longer linked to the operational Double Counter service."
  2. Exploitation: A known Metabase vulnerability let the attacker forge an administrator session (AliasFleet, TalkEsport). The sources do not give a CVE identifier.
  3. Credential harvesting: The attacker found two legitimate cloud credentials with administrative rights on the server, including a Google Cloud service-account key (TalkEsport, AliasFleet).
  4. Lateral movement into production: Those keys gave access to live cloud infrastructure, from which the attacker obtained the Discord bot token and a Stripe API key (Abijita, AliasFleet).
  5. Actions on objectives: The attacker exfiltrated about 12 GB from the database, posted malicious invites through the bot, and ran payment card testing through Stripe.

None of the sources attributes the attack to a named threat actor.

What Organizations Should Do

  1. Inventory and actually shut down retired infrastructure. Decommissioning should include network removal and credential revocation, not just taking the server out of the application. Scan your external attack surface for forgotten hosts on old providers.
  2. Patch or firewall self-hosted analytics tools. Metabase, Grafana, Superset and similar tools should never be exposed directly to the internet. Put them behind SSO or a VPN, and track their advisories as closely as you track your core stack.
  3. Remove long-lived cloud keys from servers. Replace static service-account keys with workload identity or short-lived tokens, scope them to least privilege, and alert on their use from unexpected hosts.
  4. Treat bot tokens and payment API keys as tier-0 secrets. Store them in a secrets manager, use restricted Stripe keys where possible, and have a tested rotation runbook ready.
  5. Audit the third-party bots in your Discord servers. Review the permissions they hold and the data they collect. Warn members to ignore unsolicited invites from Double Counter sent around October 4.
  6. Minimise retained verification data. If you run alt detection or fraud checks, hash or truncate IP data, set retention limits, and keep analytics replicas away from raw PII.

Sources: Hackers get away with millions of Discord IDs and email addresses i... | Popular Discord server bot breach leaks 275,000 email addresses and... | Double Counter Confirms Breach Exposing 1 Million Email Addresses -... | Double Counter - 274,922 breached accounts Today In Cyber | Double Counter Metabase Breach: Exposed Emails and Customer Data - | Double Counter Data Breach: 28M Discord IPs Leaked | Critical Alert: Recent Double Counter Data Breach | Double Counter Data Breach Exposes Discord User Data After Metabase...