Discord Bot Double Counter Breach Exposes 1 Million Emails and Millions of IDs
Published today · view counts update daily
Double Counter, a service that protects Discord servers from raids and alt accounts, has suffered a data breach that exposed about 1 million email addresses, plus Discord IDs and IP addresses for millions more users. The attackers got in on October 4 through a legacy server, held access for just under six hours, and used a stolen bot token to spam malicious links in large servers.
How the attack unfolded
In its incident report, the company described a "deliberate, multi-stage attack." The attackers exploited a vulnerability in a publicly accessible analytics tool running on a legacy server, which gave them access to cloud credentials.
Double Counter said Discord IDs and usernames for about 28 million accounts were partially copied. IP addresses and coarse location data for about 27 million accounts were also taken. The company is treating all of that data as exposed.
Paying customers were hit harder: their records also included names, countries, and postal codes.
What has leaked so far
Breach tracker Have I Been Pwned reports that 274,900 email addresses and Discord usernames have since been released publicly. That is a fraction of the roughly 1 million emails Double Counter says were exposed, so more of the data could still surface.
Abuse of the bot
The attackers also stole a bot token and used it to post malicious links in about 50 large Discord servers. Separately, they ran up $7,316 in fraudulent charges on a payment account.
Double Counter said it has disabled the stolen credentials, rotated its secrets, and moved its databases onto private networks. Service was restored on October 4, and the company notified France's data protection authority, the CNIL, on October 5.
What server owners and members should do
According to the company, regular server members don't need to take any action on their Discord accounts. Server administrators are advised to delete any suspicious Double Counter messages posted on October 4.
Bad timing for Discord
The breach lands while Discord is trying to relaunch its own age verification system. In February, the platform announced that all users would need to verify their age starting in March. Privacy concerns pushed the rollout back to the second half of 2026.
Co-founder and chief technology officer Stanislav Vishnevskiy acknowledged that Discord "should have provided more detail about [its] intentions and how the process works." The company only restarted its verification efforts at the end of last month, after adding alternative methods that don't require video selfies or ID.
Double Counter is a third-party service and not part of Discord's own infrastructure, but the incident shows how much user data ends up in the hands of community tools built around the platform.