Double Counter is a third-party anti-alt and anti-raid bot used by Discord server operators. It has confirmed a "deliberate, multi-stage attack" on October 4, 2026. The attacker got in through a forgotten legacy server running a vulnerable self-hosted Metabase instance and copied about 12 GB from one of the company's databases. Figures for the exposure vary depending on what is being counted. The company's incident report, as relayed by several outlets, says about 1 million email records and roughly 25 million user-agent hashes were copied. It also says about 28 million Discord user IDs, usernames and IP records were "partially copied." Have I Been Pwned (HIBP) lists 274,922 unique email addresses and usernames in a data set that has already been published. Discord's own platform was not breached. The exposed data was held by the bot operator.
A note on sourcing: none of the eight sources available for this brief is a primary document. Double Counter's own incident report (INC-2026-10-04) is quoted here only through secondary coverage, so treat the figures below as reported, not independently verified.
What Happened
Reconstructed from coverage of Double Counter's incident report (AliasFleet, Abijita, TalkEsport and Massively Overpowered):
- October 3: The attacker began probing a retired server from Double Counter's old OVH hosting setup, rotating through VPN addresses and working through a list of usernames (AliasFleet).
- October 4: AliasFleet says the attacker had access by 00:47 UTC and gives the main attack window as 12:03 to 17:54 UTC. Database exfiltration took place between 15:09 and 15:34 UTC. Service was restored with new credentials at 19:19 UTC. The sources do not fully explain the gap between the 00:47 access and the start of the main attack window.
- During the intrusion: The attacker took the Double Counter bot token and used it to post links to their own Discord server in about 50 large communities. Massively Overpowered says the company warned users not to accept server invites that appeared to come from Double Counter, especially any sent on Sunday, October 4.
- Payment abuse: A stolen Stripe key was used to attempt $7,316 in test charges on a company card, and charges of $3 and $15 on two customers' cards. All of them were reportedly refunded (AliasFleet, Massively Overpowered).
- October 5: Double Counter published its incident report. HIBP then indexed the leaked data set and described the incident as a Metabase-related breach.
HookPhish's breach listing gives the date as "2024-10-04", which looks like an aggregation error. Every other source puts the incident in October 2026.
What Was Taken
Counts differ depending on whether a source means data the company says was copied or data that has been published:
| Data type | Reported volume | Source |
|---|---|---|
| Discord user IDs and usernames | ~28M, "partially copied" and treated as exposed | Company report via S1, S6, S8 |
| IP address plus coarse geolocation (country, region, city, postcode, ISP) | ~27M records | Company report via S6, S8 |
| User-agent hashes (one-way hash of browser UA, city and country, used for alt detection) | ~25M | Company report via S1, S8 |
| Email records copied | ~1M (about 840k "Doogle" accounts and ~240k dashboard and customer contacts) | Company report via S1, S3, S8 |
| Emails and usernames in the public leak | 274,922 unique | HIBP via S2, S4, S7 |
| Paying-subscriber records (name, country, postcode, processed via Stripe) | "A small number" | HIBP via S2, S5 |
| Total data copied | ~12 GB from one database | S3, S8 |
The two email figures do not contradict each other. Roughly 1 million email records were copied, and about 275,000 of them have surfaced publicly so far. PC Guide reports that 25% of the published addresses were already in HIBP from earlier breaches. Reports say Discord passwords and full card numbers were not exposed (TalkEsport, Massively Overpowered).
The most sensitive part of the data set is the IP and geolocation table. As AliasFleet points out, those records belong to people who simply clicked a verification link to join a server, and most never signed up for Double Counter directly.
Why It Matters
- Third-party bots hold more data than users expect. Double Counter says it has protected over 618,000 servers and verified more than 118 million accounts (PC Guide). The bot does its job by storing IP addresses and browser fingerprints. Server operators passed that data collection on to their members, often without the members realising.
- IP data tied to a Discord identity enables real-world harm. It can be used for doxxing, swatting, harassment, and targeted social engineering of gaming and crypto communities, where Discord is the main channel of communication.
- The stolen bot token shows how a vendor compromise turns into a phishing campaign. A trusted bot posting malicious invites in large servers is effective phishing. Any bot with wide server permissions is a supply-chain risk to every community that installs it.
- The root cause was neglected infrastructure. No novel technique was involved. A decommissioned server that stayed online, an unpatched analytics tool, and cloud credentials left on disk were enough to give the attacker the path in.
The Attack Technique
Sources broadly agree on the intrusion chain:
- Initial access: A legacy OVH server was still publicly reachable after decommissioning and still ran a self-hosted Metabase instance. According to AliasFleet, the company said the server was "no longer in use and no longer linked to the operational Double Counter service."
- Exploitation: A known Metabase vulnerability let the attacker forge an administrator session (AliasFleet, TalkEsport). The sources do not give a CVE identifier.
- Credential harvesting: The attacker found two legitimate cloud credentials with administrative rights on the server, including a Google Cloud service-account key (TalkEsport, AliasFleet).
- Lateral movement into production: Those keys gave access to live cloud infrastructure, from which the attacker obtained the Discord bot token and a Stripe API key (Abijita, AliasFleet).
- Actions on objectives: The attacker exfiltrated about 12 GB from the database, posted malicious invites through the bot, and ran payment card testing through Stripe.
None of the sources attributes the attack to a named threat actor.
What Organizations Should Do
- Inventory and actually shut down retired infrastructure. Decommissioning should include network removal and credential revocation, not just taking the server out of the application. Scan your external attack surface for forgotten hosts on old providers.
- Patch or firewall self-hosted analytics tools. Metabase, Grafana, Superset and similar tools should never be exposed directly to the internet. Put them behind SSO or a VPN, and track their advisories as closely as you track your core stack.
- Remove long-lived cloud keys from servers. Replace static service-account keys with workload identity or short-lived tokens, scope them to least privilege, and alert on their use from unexpected hosts.
- Treat bot tokens and payment API keys as tier-0 secrets. Store them in a secrets manager, use restricted Stripe keys where possible, and have a tested rotation runbook ready.
- Audit the third-party bots in your Discord servers. Review the permissions they hold and the data they collect. Warn members to ignore unsolicited invites from Double Counter sent around October 4.
- Minimise retained verification data. If you run alt detection or fraud checks, hash or truncate IP data, set retention limits, and keep analytics replicas away from raw PII.
Sources: Hackers get away with millions of Discord IDs and email addresses i... | Popular Discord server bot breach leaks 275,000 email addresses and... | Double Counter Confirms Breach Exposing 1 Million Email Addresses -... | Double Counter - 274,922 breached accounts Today In Cyber | Double Counter Metabase Breach: Exposed Emails and Customer Data - | Double Counter Data Breach: 28M Discord IPs Leaked | Critical Alert: Recent Double Counter Data Breach | Double Counter Data Breach Exposes Discord User Data After Metabase...