A cyberattack on Double Counter, a popular security bot used by Discord communities, has potentially exposed information associated with approximately 28 million accounts. The breach also allowed an attacker to hijack the bot and distribute unwanted invitations across dozens of servers.
Double Counter helps Discord communities verify members and identify suspicious or duplicate accounts. The incident affected the independent service rather than Discord’s own infrastructure.
According to Double Counter, the attacker entered its systems through an outdated server that was no longer used for daily operations. A vulnerability in an exposed analytics tool allowed the intruder to obtain administrator credentials and reach the company’s cloud environment.
The attacker remained active in the cloud infrastructure for nearly six hours on October 4 and copied approximately 12 GB of information.
Double Counter estimates that the affected database contained usernames and Discord IDs associated with around 28 million accounts. It also held IP addresses and approximate location information relating to roughly 27 million accounts, along with browser-related identifiers and approximately one million email addresses.
Not all of those records were necessarily downloaded. However, because the company cannot identify every individual record copied, it is treating the potentially affected information as exposed.
The attacker also obtained the bot’s authentication token, allowing them to impersonate Double Counter within Discord. Using that access, they posted invitations to their own server in approximately 50 large communities.
The incident extended to financial fraud when the attacker obtained a payment-service key associated with another product operated by the same company. Fraudulent transactions totaled $7,316 against a company card, while two customers were charged an additional $18. Both customers received refunds.
Double Counter emphasized that Discord passwords and stored payment-card numbers were not exposed. A separate database containing information associated with approximately 58 million users was also unaffected.
The company says it has removed the attacker, replaced compromised credentials, secured its infrastructure, and restored normal service. An investigation found no remaining unauthorized access.
Discord users whose information was exposed may face an increased risk of phishing or impersonation attempts, particularly if their email addresses were included. Double Counter advises users to avoid unexpected server invitations sent through its bot.
The company has notified France’s data protection authority and is pursuing legal action against those responsible. Its investigation remains ongoing.
