Double Counter, a Discord bot used to verify members and block alternate accounts, has suffered a data breach. Have I Been Pwned has listed roughly 275,000 unique email addresses from data published online, alongside Discord usernames.
The wider exposure could affect far more users. Double Counterโs incident table puts the number of copied email addresses at around one million, with other affected datasets containing millions of Discord IDs and IP records.
In brief:
- Have I Been Pwned lists approximately 275,000 unique email addresses in the publicly released data.
- Double Counterโs incident table says around one million email addresses were copied overall.
- Attackers reportedly stole about 12 GB of data and used the bot to post links in around 50 large Discord servers.
- Double Counter says it revoked access, rotated credentials, and restored service.
What Happened in the Double Counter Breach?
The attack took place on October 4, 2026. Have I Been Pwned attributes the breach to a vulnerability in the Metabase analytics tool.
In its Discord announcement, Double Counter says attackers used an old production server to reach its former OVH server and a Google Cloud session. They then exploited the botโs token and exported part of a database.
Reporting from AliasFleet, citing the detailed incident report, puts the main attack window at roughly six hours and the copied data at about 12 GB. The stolen bot token was also used to send invitations to the attackerโs server through around 50 large communities.
What Data Was Exposed?
Double Counterโs incident table lists the following affected data:
| Data type | Approximate records | Reported status |
|---|---|---|
| Email addresses | 1 million | Copied |
| Browser user-agent hashes | 25 million | Copied |
| Discord IDs and usernames | 28 million | Partly copied, treated as exposed |
| IP addresses and coarse location data | 27 million | Partly copied, treated as exposed |
These figures cover different datasets and should not be added together as a total number of victims. The table also lists VPN detection logs as not copied, behavioural fingerprints as stored elsewhere and not copied, and cold storage as unaffected.
Have I Been Pwnedโs smaller figure refers to unique email addresses in the publicly released data it recorded. It also reports that a small number of paying subscribers had names, countries, and postcodes exposed.
Double Counter Restores Service After the Attack
Double Counterโs announcement says known access was revoked, secrets were rotated, and the bot was operational again.
Payment abuse was also reported. According to AliasFleetโs account of the incident report, attackers made $7,316 in test charges on a company card, plus charges of $3 and $15 on two customersโ cards. All were reportedly refunded.
What Discord Users Should Do Now ASAP
Be cautious with unexpected verification requests, server invitations, and emails claiming to come from Discord. Messages referencing your actual username may still be scams.
- Check your email address on Have I Been Pwned.
- Enable two-factor authentication on Discord and your email account.
- Open Discord directly when checking account alerts.
- Avoid entering login details through unsolicited links.
Server owners should review suspicious bot messages and alert members who may have clicked them.
