Discord Users Hit by Massive Data Theft from Security Partner Double Counter

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
A deliberate, multi-stage attack on October 4, 2026, against Double Counter, a key third-party security service for Discord servers, has resulted in the theft of an estimated 1 million email addresses and data linked to around 28 million Discord user accounts. While Discord itself wasn't directly breached, hackers exploited a vulnerability in Double Counter legacy infrastructure to gain extensive access, compromising user IDs, IP addresses, and user-agent hashes. This incident marks another significant security setback for the gaming chat giant, highlighting the persistent risks associated with third-party vendors. The attackers spent nearly six hours inside Double Counter systems, leveraging a flaw in a publicly accessible Metabase analytics tool on an old, forgotten server to obtain critical cloud credentials and a Discord bot token. With this access, they not only exfiltrated approximately 12 GB of sensitive user data but also posted malicious links in about 50 large Discord servers and conducted fraudulent charges totaling over $7,300 using a stolen payment key from an associated product. This breach echoes past security concerns for Discord, coming almost a year after a similar incident involving a compromised customer service partner that exposed government ID images. Discord is also currently attempting to relaunch its age verification system, further complicating its privacy narrative. In response, Double Counter, owned by Tellter, quickly disabled the stolen credentials, rotated its secrets, and moved its databases to private networks, restoring service on the same day, October 4, 2026. France's data protection authority, the CNIL, was notified on October 5. Discord has temporarily halted new installations of the Double Counter app and is working with the company to understand the full scope of the compromise. Users are advised that Discord passwords were not exposed, but server administrators should delete any suspicious messages from October 4, and all users should remain vigilant against potential phishing attempts using the stolen email addresses.