Double Counter Security Breach: 28 Million Discord Accounts Exposed in Major Cloud Intrusion

Discord security infrastructure took a massive hit this week. Double Counter, one of the most widely used verification and anti-raid bots protecting competitive gaming communities, suffered a major cloud breach compromising millions of user records.
The development team maintained full transparency by publishing an extensive incident report detailing the October 4, 2026 cyberattack. Here is an exact breakdown of what happened, what data was exposed, and what actions community managers need to take immediately.
Vulnerability in Legacy Analytics Led to Cloud Compromise
According to technical findings shared by Double Counter, the attackers initiated their breach by exploiting an analytics tool hosted on a legacy server. This initial foothold allowed them to extract privileged access credentials.
With those credentials in hand, the intruders infiltrated Double Counter's secure cloud infrastructure. They maintained unauthorized access for nearly six hours before the engineering team identified the anomaly and severed all compromised connections.
12GB of Extracted Data: What Leaked and What Remained Safe
The attackers managed to exfiltrate approximately 12GB of data before being locked out. While the scale of exposed accounts is significant, examining the exact nature of the compromised records clarifies the actual threat level.
Forensic log analysis revealed the following breakdown of compromised user information:
- 28 million accounts: Discord user IDs and partial usernames copied.
- 27 million accounts: IP addresses and approximate geolocation details.
- 25 million accounts: Device fingerprints and user-agent hashes.
- 1 million accounts: Associated email addresses.
Crucially, critical protective barriers remained intact. More than 15 million VPN detection logs were completely untouched, and the perpetrators failed to download or export the full production database.
From a financial standpoint, no account passwords or full payment card numbers are ever stored on Double Counter servers, as transactions are handled directly by certified payment processors. Only three premium subscription cards saw unauthorized charges totaling roughly $7,300 before payment API keys were revoked at 17:14 UTC.

Bot Token Hijacking and Criminal Charges Filed
Beyond data exfiltration, the attackers briefly hijacked the bot's official Discord token. They used this access to broadcast spam and phishing links pointing to their own server across roughly 50 prominent Discord servers.
Legal retaliation followed swiftly. With extensive forensic logs and connection data captured during the attack, Double Counter identified the individuals responsible and filed criminal complaints in both France and the United States.
Essential Security Steps for Server Administrators and Users
If your community relies on Double Counter, check your server Audit Logs immediately for any actions executed by the bot on October 4 between 12:00 and 16:30 UTC. Reversing unauthorized role changes or channel permissions during that timeframe is essential.
This incident underlines why strict permission boundaries are mandatory when you set up a Discord bot across any competitive or gaming hub.
Regular users should ignore and report any direct messages claiming to represent Double Counter or urging verification updates. With 1 million email addresses leaked, high-priority phishing campaigns targeting Discord accounts will likely surge in the coming weeks.



















