A popular Discord security bot designed to block alternate accounts suffered a data breach that exposed information linked to roughly 28 million user accounts, including about 1 million email addresses, according to the operator’s official incident report published October 5.
Double Counter, run by the Paris-based company Tellter SAS and installed in more than 600,000 Discord communities, records IP addresses and other details during its verification process to detect alt accounts, ban evasion and raids. On October 4, 2026, an attacker gained access to the service’s systems through a forgotten legacy server and copied approximately 12 gigabytes of database content in about 25 minutes.
The company published a detailed security incident report on October 5 stating that Discord user IDs and usernames for about 28 million accounts were partly copied and are being treated as exposed, according to the report at doublecounter.gg/blog/security-incident-october-2026. IP addresses and coarse geolocation data — country, region, city, postal code and internet service provider — tied to roughly 27 million accounts received the same treatment. About 25 million user-agent hashes were also copied, along with approximately 1 million deduplicated email addresses.
Discord passwords were never collected by the service and were not involved. A separate cold-storage database holding data on about 58 million users remained untouched, the report said. Payment card numbers stored with the payment provider were not exposed either.
The intrusion began on a retired OVH server from the company’s previous hosting setup that was still publicly reachable and running an outdated self-hosted analytics tool called Metabase. The attacker probed the server from rotating VPN addresses starting early on October 3, then exploited a vulnerability in Metabase on October 4 to obtain cloud credentials with administrator privileges. No specific Common Vulnerabilities and Exposures identifier was provided.
Once inside the live cloud environment, the attacker spent 5 hours and 51 minutes active — from 12:03 to 17:54 UTC — extracting a Discord bot token, using it to post invitation links to their own server in about 50 large communities, and copying database tables. Staff repeatedly rotated credentials, but the attacker adapted quickly, reading a newly issued bot token within two minutes on one occasion.
The attacker also obtained a Stripe payment key belonging to Atis, another Tellter product, and ran a series of test charges totaling $7,316 against a company card. Two small charges to Atis customers — $3 and $15 — were refunded in full. Tellter said customer funds remain safe and that no other cards were affected.
Tellter, whose president and founder is Nathan Lourenço, shut down the attacker’s access the same day, audited its systems for persistence, rotated secrets and restored the service at 19:19 UTC. The company notified France’s data protection authority, the CNIL, and said it is filing criminal complaints in France and the United States.
Discord confirmed it is aware of the incident involving the third-party app. In a statement provided to Dexerto, the platform said: “While this was not a breach of Discord, we’ve disabled new installs of the app while we work with Double Counter to understand the full scope of the incident, and we’ll take further action as appropriate.”
A portion of the stolen data later appeared publicly. Have I Been Pwned added a corpus containing roughly 275,000 unique email addresses and Discord usernames to its database on October 7. Records belonging to some paying customers also included names, countries and postal codes. Tellter’s report had estimated approximately 1 million deduplicated email addresses across its services; the Have I Been Pwned corpus represents the subset publicly released so far.
Server administrators were advised to delete any Double Counter messages posted on October 4 between 12:00 and 16:30 UTC that invited users to another server and to review their audit logs for related activity. Users who supplied an email address to the service were told to remain alert for phishing attempts.
Double Counter has operated since 2020 as one of the most widely used verification tools on the platform, relying on IP matching, device fingerprinting and other signals to flag alternate accounts within seconds of a user joining a protected server.
The breach adds to a growing list of third-party security incidents affecting Discord’s ecosystem. Hypefresh previously reported on an earlier Discord data breach that exposed user information, as well as a YouTube doxing exploit that exposed partnered YouTuber emails. Other platform security incidents covered by Hypefresh include an Instagram data leak affecting 17.5 million U.S. accounts, high-profile Instagram accounts hijacked via Meta’s AI support chatbot, and Chick-fil-A urging customers to reset passwords after a hacker breach.
According to GBHackers, the attacker first probed the legacy OVH server on October 3 from rotating VPN addresses, then exploited the Metabase vulnerability at 00:47 UTC on October 4 to forge an administrator session. InformedClearly reported that at 12:26 UTC the attacker accessed a running bot container’s shell and extracted the Discord token, then granted themselves administrator privileges on Double Counter’s support server and distributed invitations to their own server in about 50 large communities. Cybernews noted the attacker made escalating test charges of $1, $10, $100 and $1,000 against a company card, totaling $7,316. GamesIndustry.biz confirmed Discord disabled new Double Counter installs while investigating, meeting GDPR’s 72-hour disclosure window with the CNIL notification on October 5.


