Double Counter Breach Exposes Data Tied to 28 Million Discord Accounts
The company says the copied records included email addresses for 1 million accounts, IP and coarse location data for 27 million, and user-agent hashes for 25 million.

A breach at Double Counter, a provider of server-wide security tools for Discord communities, exposed data tied to as many as 28 million accounts. The company says account IDs and usernames were partly copied, while other stolen records included IP addresses, coarse location data, user-agent hashes, and email addresses.
Double Counter said the attack happened on October 4. In its incident report, the company described attackers exploiting a vulnerability in an analytics tool still running on a server from its previous hosting setup. They used credentials found there to reach its cloud infrastructure, spent nearly six hours inside the system, and copied 12 GB of data.
The attacker also took control of Double Counter’s Discord bot token and used it to post links to their own server in about 50 large Discord servers. A stolen payment key was used for separate financial fraud, with more than $7,300 in fraudulent charges detected. Double Counter says three cards were charged, one belonging to the company and two to customers. It says no other customers were affected by the payment fraud, customer funds are safe, and stored card numbers were not exposed.
Not all of the provider’s data was taken. Double Counter says 15 million VPN-detection logs were not copied, and the attacker did not obtain a complete export of the affected database. The company has engaged legal counsel and says it is pursuing those responsible in France and the United States. A criminal complaint is being prepared.
Double Counter advised ordinary Discord members that they do not need to change their account settings, but warned them not to join servers promoted through Double Counter profiles. Anyone who received messages from those profiles should delete them. Server owners were also advised to check their audit logs for actions made by Double Counter on October 4 between 12:00 and 16:30 UTC, and remove any they find.
What safeguards should Discord bot providers prioritize when an attacker gets control of a bot token? For more on the breach and its fallout, stay connected on X, Bluesky, YouTube, Instagram, Steam, and Telegram.




