Double Counter, a security bot used by Discord communities, has suffered a security breach that exposed user information.
The incident happened on October 4, 2026, after an attacker gained access to the company’s cloud environment. Around 12 GB of database information was copied, while a stolen Discord bot token was later used to send unwanted invitations to about 50 large servers.
Double Counter says the incident has been contained and its services were restored. The company also reviewed 14 cloud projects and found no evidence of persistent backdoors. The incident affected Double Counter’s own infrastructure and does not indicate that Discord itself was breached.
How the Attacker Got In
The attack started with an old OVH server that Double Counter had used for hosting in the past.
Although the server was no longer part of the main service, it still had a publicly accessible analytics tool called Metabase. The attacker exploited a weakness in the setup to gain administrator access and retrieve credentials stored on the server.
Among the stolen information was a cloud account with high-level permissions and a saved administrator session. These credentials gave the attacker a path from the old server into Double Counter’s active cloud environment.
The attacker then added an SSH key, accessed cloud resources, and opened a shell inside a bot container. This eventually exposed the Discord bot token.
Stolen Token Used Against Discord Servers
The compromised token gave the attacker control over parts of Double Counter’s Discord presence.
They used it to give their account administrator permissions on a support server, restore a previously banned account, and send invitations to other Discord communities.
Double Counter initially replaced the stolen bot token, but the attacker was able to obtain the new token within minutes because their cloud access was still active.
This was an important lesson from the incident: changing a password or token is not enough if the attacker still controls the system that can access the replacement secret.
The attacker later accessed database records and copied information during several stages of the attack. Access was finally stopped after the company revoked the compromised cloud sessions and credentials.
What Data Was Exposed?
Double Counter estimates that several datasets may have been exposed, including:
- Discord IDs and usernames
- IP address and location information
- User-agent hashes
- Approximately one million unique email addresses
The company noted that these datasets overlap, so the figures should not be added together to estimate the total number of affected users.
Double Counter says Discord passwords and stored payment card information were not exposed. Separate cold-storage data covering millions of users was also unaffected.
The company has since shut down the old server, revoked compromised access, rotated credentials, removed exposed webhooks, and moved databases behind private networking.
The incident is another reminder that unused infrastructure can become a serious security risk. Old servers, forgotten applications, saved credentials, and inactive cloud resources should be regularly reviewed and removed when they are no longer needed.