Earlier this week, a platform called Double Counter, a provider that offers server-wide protection for the Discord ecosystem, suffered a widespread data breach. The provider ‘blocks alt accounts, raids, and VPNs’ and is ‘built on millions of curated data points across hte largest Discord security network’, but a recent critical breach led to countless users being exposed.
In a transparent incident report published publicly, Double Counter confirmed that the attack, which happened on October 4th, resulted in 12 GB of data being copied after hackers were able to spend almost six hours inside a secure cloud system. As a result, more than one million Discord email addresses were copied and taken.
Discord Breach Results in Huge Exposure
Double Counter, a security provider working closely with Discord to protect servers, wrote in an incident report:
On 4 October 2026, Double Counter was the target of a deliberate, multi-stage attack. The attacker broke into a server from our previous hosting setup through a vulnerability in an analytics tool it was still running, then used credentials found on that server to reach our cloud infrastructure and adapted to each of our containment steps.
During the attack they took control of the bot’s Discord token, used it to post links to their own Discord server in about 50 large servers, copied part of one of our databases, and used a stolen payment key to commit financial fraud on a separate account.
In a step-by-step breakdown with timestamps, which is extremely refreshing to see from someone with an Incident Management background, the team confirmed what happened, how it happened, and, more importantly, what was impacted by the breach.
Like, I can’t stress to you enough… The depth of their report was phenomenal.
They confirmed that:
- 28 million accounts had their IDs and usernames ‘partly copied’
- 27 million accounts had their IP addresses and coarse geolocation data ‘partly copied’
- 25 million accounts had their user-agent hashes copied
- 1 million accounts had their email address ‘copied’
But the silver lining here is that 15 million VPN detection logs were not copied, and a full export of the affected database was also not successfully copied or downloaded.
Double Counter also confirmed that customer funds are safe despite more than $7,300 in fraudulent charges being detected, which is a saving grace:
Only three cards were charged in total — one of our own and two customers’ — and no other customers were affected. We revoked every payment-provider key at 17:14, rotated the credentials and secured the accounts. All customer funds are safe. No stored card numbers were exposed: the payment provider holds those, and the attacker acted through the account, not the card data.
Now, the legal battle begins:
We have engaged legal counsel and are pursuing those responsible in both France and the United States. A criminal complaint is being filed, and our lawyers are building the case on platform and Discord logs, direct-message screenshots, and technical indicators collected from our own systems.
RELATED: GTA 6 Leak Reveals Discord Promotion
What To Do After The Discord Breach
The team advised that you should delete any DMs or messages sent from any Double Counter profile and check your ‘audit log’ if you’re a server owner, looking for and eliminating any actions made by Double Counter on October 4th from 12:00 to 16:30 UTC.
Discord members have nothing to change on their account, but they should absolutely refrain from joining any servers ‘seemingly promoted’ by Double Counter.
From what we can see, Discord has yet to address this breach, but if it does, it’ll likely direct you to the incident report I’ve linked above.
Are you fearing for your safety on Discord after this breach? Let us know your thoughts on the Insider Gaming Discord server.
For more Insider Gaming coverage, check out the full patch notes for ARC Raiders’ Frozen Trail update, and don’t forget to sign up for our newsletter.




Comments