Change language to
0:00

Double Counter, a bot that Discord server owners use to block alt accounts, raids and VPNs, says an attacker copied data linked to up to 28 million Discord accounts on 4 October. Discord itself wasn’t breached, and the provider says no passwords or stored card numbers were exposed.

Insider Gaming reports that the attacker spent almost six hours inside Double Counter’s cloud systems and copied about 12 GB of data. In its public incident report, Double Counter says the attacker got in through a vulnerability in an analytics tool still running on a server from its previous hosting setup. Credentials found there gave the attacker access to its cloud infrastructure, and the attacker adapted to each containment step.

Subscribe to our Newsletters for more Tech Stories

What was copied

Double Counter’s figures, as relayed by Insider Gaming and Cybernews, are approximate and describe partial copies of one database:

DataAccounts affected
Discord user IDs and usernames~28 million
IP addresses and coarse geolocation~27 million
User-agent hashes~25 million
Email addresses~1 million

Cybernews adds that the location data covers country, region, city, postal code and ISP. Double Counter says about 15 million VPN detection logs weren’t copied, and that they couldn’t download a full export of the affected database.

Bot hijack and fraud

The attacker also stole the bot’s Discord token. They used it to post invites to their own Discord server in about 50 large communities that use Double Counter. The attacker used a stolen payment key to commit fraud on a separate account: Cybernews puts the total at $7,316, with only three cards charged, including one of Double Counter’s own. Two customers were also charged $18 in total and refunded. Double Counter says all customer funds are safe, and that the payment provider, not the attacker, holds card numbers.

The company says it has hired legal counsel, is filing a criminal complaint and is pursuing those responsible in France and the United States.

What to do now

Double Counter’s advice, as reported by Insider Gaming, is that ordinary members don’t need to change anything on their accounts. Instead:

  • Delete any DMs or messages from a Double Counter profile.
  • Don’t join servers that Double Counter appears to promote.
  • If you run a server, check the audit log for actions by Double Counter between 12:00 and 16:30 UTC on 4 October and remove them.

With emails and IP-linked location data in play, it’s sensible to watch for phishing that references your Discord activity and to treat unexpected invites with suspicion. That is general precaution, not a recommendation from the incident report. As of Insider Gaming’s report, Discord hadn’t publicly addressed the breach.

The story is part of a wider pattern: third-party tools become the weak point for platforms that were otherwise secure. For background on a different Discord-linked leak, see our coverage of the GTA 6 leaks and Rockstar’s statement.

Were GCC users affected?

Neither Double Counter’s report nor the coverage we’ve read gives a regional breakdown, so there’s no verified count of UAE or wider GCC accounts. The figures are global.

Do I need to change my Discord password?

According to Double Counter, no. It says no passwords were exposed and that members don’t need to change anything on their accounts.

How do I check whether a server I run was affected?

Open your server’s audit log and look for any actions made by Double Counter on 4 October between 12:00 and 16:30 UTC. Remove anything you didn’t authorise.