Discord Users’ Data Exposed in Security Bot Double Counter Security Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Double Counter, a Discord security bot, has disclosed a breach that exposed user data after an attacker broke into its cloud systems on October 4, 2026. Attackers copied about 12 GB of database records, and the stolen bot token was used to post unwanted invitations across roughly 50 large Discord servers.

According to Double Counter’s official incident report, the attack is contained and service was restored at 19:19. Investigators audited 14 cloud projects and found no backdoors. The breach involved the bot provider’s infrastructure, not a confirmed compromise of Discord itself.

Double Counter Security Breach

The attacker entered through an old OVH server from Double Counter’s previous hosting setup. Although disconnected from the live service, it still ran a publicly reachable Metabase analytics tool. A flaw let the attacker forge an administrator session and access credentials stored on the host.

Those secrets included a cloud service-account key with administrator rights and an administrator’s saved command-line session. This turned an unused server into a bridge to production systems. Because the attacker reused valid identities rather than creating accounts, their activity initially looked less suspicious.

Cybersecurity News previously reported on an actively exploited Metabase flaw. However, Double Counter’s disclosure does not name a CVE or advisory, so linking this incident to that specific vulnerability would be premature.

Cloud access began at 12:03. The attacker added an SSH key, exported a database into a storage bucket, and opened a shell inside a bot container. That shell exposed the Discord token. The attacker never downloaded the first database export.

The stolen token let the attacker grant their account administrator rights on the support server, reverse a staff ban, and send invitations under Double Counter’s identity.

Staff invalidated the token at 13:39, but restoring the bot with a replacement did not remove the attacker’s cloud access. They read the new token within two minutes. This shows why changing one secret cannot contain an attack while the system holding that secret remains compromised.

The attacker later changed the database administrator password and copied records between 15:09 and 15:34. Revoking the service-account key also proved insufficient: they switched to the stolen administrator session. Access ended only after they revoked those sessions around 17:55.

Double Counter treats approximately 28 million Discord IDs and usernames and 27 million IP-address and location records as exposed. It also reports copied user-agent hashes covering about 25 million accounts and roughly one million unique email addresses. These groups overlap, so adding them would overstate the number of victims.

Only part of the larger IP-address table was copied. Because investigators cannot identify which rows were left out, they count the entire table as exposed. Have I Been Pwned lists roughly 275,000 unique email addresses in publicly released data, a smaller dataset than the provider’s reported exposure.

Discord passwords and stored card numbers were not exposed. Cold storage covering roughly 58 million users remained unaffected. A stolen Stripe key enabled $7,316 in fraudulent charges against a company card on the separate Atis account. Two customer charges were refunded.

Responders shut down the old server, revoked cloud access, rotated credentials, deleted exposed webhooks, and moved databases behind private networking. The token now uses dedicated secret storage. Secret-access logging and continuous monitoring now support the restored service.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Discord Users’ Data Exposed in Security Bot Double Counter Security Breach appeared first on Cyber Security News.