Double Counter Data Breach: 275,000 Emails Published Online

Abu Taher Tamim
By Abu Taher Tamim
4 Min Read
Image Credit: Discord

Double Counter, a Discord bot used to verify members and block alternate accounts, has suffered a data breach. Have I Been Pwned has listed roughly 275,000 unique email addresses from data published online, alongside Discord usernames.

The wider exposure could affect far more users. Double Counterโ€™s incident table puts the number of copied email addresses at around one million, with other affected datasets containing millions of Discord IDs and IP records.

In brief:

  • Have I Been Pwned lists approximately 275,000 unique email addresses in the publicly released data.
  • Double Counterโ€™s incident table says around one million email addresses were copied overall.
  • Attackers reportedly stole about 12 GB of data and used the bot to post links in around 50 large Discord servers.
  • Double Counter says it revoked access, rotated credentials, and restored service.

What Happened in the Double Counter Breach?

The attack took place on October 4, 2026. Have I Been Pwned attributes the breach to a vulnerability in the Metabase analytics tool.

In its Discord announcement, Double Counter says attackers used an old production server to reach its former OVH server and a Google Cloud session. They then exploited the botโ€™s token and exported part of a database.

Reporting from AliasFleet, citing the detailed incident report, puts the main attack window at roughly six hours and the copied data at about 12 GB. The stolen bot token was also used to send invitations to the attackerโ€™s server through around 50 large communities.

What Data Was Exposed?

Double Counterโ€™s incident table lists the following affected data:

Data typeApproximate recordsReported status
Email addresses1 millionCopied
Browser user-agent hashes25 millionCopied
Discord IDs and usernames28 millionPartly copied, treated as exposed
IP addresses and coarse location data27 millionPartly copied, treated as exposed

These figures cover different datasets and should not be added together as a total number of victims. The table also lists VPN detection logs as not copied, behavioural fingerprints as stored elsewhere and not copied, and cold storage as unaffected.

Have I Been Pwnedโ€™s smaller figure refers to unique email addresses in the publicly released data it recorded. It also reports that a small number of paying subscribers had names, countries, and postcodes exposed.

Double Counter Restores Service After the Attack

Double Counterโ€™s announcement says known access was revoked, secrets were rotated, and the bot was operational again.

Payment abuse was also reported. According to AliasFleetโ€™s account of the incident report, attackers made $7,316 in test charges on a company card, plus charges of $3 and $15 on two customersโ€™ cards. All were reportedly refunded.

What Discord Users Should Do Now ASAP

Be cautious with unexpected verification requests, server invitations, and emails claiming to come from Discord. Messages referencing your actual username may still be scams.

  • Check your email address on Have I Been Pwned.
  • Enable two-factor authentication on Discord and your email account.
  • Open Discord directly when checking account alerts.
  • Avoid entering login details through unsolicited links.

Server owners should review suspicious bot messages and alert members who may have clicked them.

By Abu Taher Tamim Staff Writer
Follow:
Abu Taher Tamim is a Staff Writer at GameRiv. He started playing video games when one of his uncles brought him a PS1, after it was launched. Since that day until now, he still play video games. As he loves video games so much, he became a gaming content writer.