Top 5 This Week

Related Posts

Double Counter Data Breach Leaks IP Addresses of 28 Million Discord Users

An attacker broke into Double Counter on October 4 and copied IP addresses, locations and usernames tied to 28 million Discord accounts. Here's what leaked, what didn't, and the steps members and server admins should take now.

The Double Counter data breach exposed Discord user IDs, usernames and IP addresses for about 28 million accounts after an attacker broke into the bot’s systems on October 4, 2026. Roughly 27 million of those records also include location and internet provider details. Around 1 million email addresses were taken too. Discord passwords and card numbers were outside the leak.

If you ever clicked a Double Counter verification link to get into a Discord server, assume your record was copied.

What Is Double Counter and Why Did It Store Your IP Address?

Double Counter is a verification bot that Discord servers use to stop alt accounts. When you join a server that uses it, you click a link and the bot checks your IP address and browser details against everyone else who has verified. If two accounts match, the bot flags one as a possible alt. Dexerto reports the bot runs in more than 600,000 communities.

- Advertisement -

To catch alts, the bot has to store exactly the kind of data that makes a leak dangerous. That’s where this breach does its damage.

How the Double Counter Hack Happened

The attacker got in through an old server the team no longer used. It was a legacy OVH machine still running a public Metabase analytics dashboard with a known flaw. On that machine, the attacker found two cloud credentials with admin rights, including a Google Cloud service-account key, and used them to reach the live systems.

Here is the timeline from Double Counter’s incident report, as summarized by The CyberSec Guru’s breakdown of the incident report. All times are UTC.

Date and time (UTC)What happened
Oct 3, 04:37Attacker starts probing the old OVH server through rotating VPN addresses
Oct 4, 00:47First access through the Metabase vulnerability
Oct 4, 12:03Stolen Google Cloud key used for the first time
Oct 4, 12:26Bot token pulled from a running container
Oct 4, 13:30 to 16:30Bot posts invite spam in about 50 large Discord servers
Oct 4, 15:09 to 15:34About 12 GB of database tables copied out
Oct 4, 17:11Fraudulent payment charges begin
Oct 4, 17:54Last recorded attacker action
Oct 4, 19:19Service restored with new credentials
Oct 5Breach reported to regulators and disclosed publicly

The attacker was active inside the systems for 5 hours and 51 minutes. Dexerto reports that when staff changed the bot’s credentials, the attacker had the new ones about two minutes later.

What Data Was Leaked in the Double Counter Breach

Data typeApproximate accounts affected
Discord user IDs and usernames28 million
IP addresses with country, region, city, postal code and ISP27 million
User-agent hashes (browser fingerprints)25 million
Email addresses1 million

The email figure combines about 840,000 Doogle account holders and about 240,000 dashboard users and customer contacts, after removing duplicates. PC Guide reported a much lower number: 275,000 unique email addresses with usernames. The gap probably comes from counting methods. Double Counter’s own report says about 1 million, so plan around that.

The attacker didn’t get every IP record before the team cut access. Double Counter can’t tell which ones left, so it is treating all of them as exposed.

What Stayed Safe

Your Discord password was never at risk, because Double Counter never receives it. Login happens on Discord’s side. The report says no stored card numbers were exposed either, since the payment provider holds that data.

Double Counter also says the attacker never touched its VPN detection logs, its behavioral fingerprint database or its cold-storage database.

The Attack Also Hit Servers and Payments

Using the stolen bot token, the attacker posted invites to their own server in around 50 large Discord communities. Members saw the messages come from a bot they trusted, which is the reason admins are being told to delete them.

The attacker also took a Stripe key belonging to Atis, a separate product from the same team, and pushed through $7,316 in fraudulent charges. Two of those were charges to customers, for $3 and $15. Both have been refunded.

Why a Leaked IP Address Matters

An IP address by itself won’t hand anyone your house key. Combined with a username, a city, a postal code and an ISP, it gets much closer to a real person. That pairing is valuable to scammers, doxxers and anyone holding a grudge from a server argument.

These are the same records courts and police ask platforms for when they need to tie an online account to a real identity. A judge recently ordered Discord to hand over account and device records in the GTA 6 leak case, and platform reports also led to an FBI arrest over a Fortnite player’s voice chat threats. Now that kind of data is in an attacker’s hands, with no court order involved.

Am I Affected by the Double Counter Leak?

If you have verified through Double Counter in any Discord server, assume yes. At the time of writing, no public lookup tool exists to check single accounts, and the team itself can’t confirm which IP records left.

The email list is smaller. You are most likely on it if you had a Doogle account, used the Double Counter dashboard, or paid for a premium plan.

What Discord Users Should Do Now

Turn on multi-factor authentication first. Discord’s guide to setting up multi-factor authentication walks through passkeys, authenticator apps and SMS codes. Discord itself advises against SMS, so pick a passkey or an authenticator app.

Then expect phishing. Anyone holding your email, username and city can write a message that sounds believable. Ignore DMs or emails asking you to “re-verify,” “restore your server access” or “confirm your Double Counter account.” Valve warned about the same kind of follow-up scams after the Steam data breach that exposed EU hardware buyers’ details earlier this year.

ActionWhy it helps
Enable a passkey or authenticator app on DiscordStops account takeover even if your email gets phished
Treat “verification” messages as suspiciousAttackers can reference real servers and usernames
Restart your router if your ISP gives dynamic IPsYou may get a new IP, which makes the leaked one stale
Use a VPN in large public serversKeeps your home IP out of future verification logs
Change your email password if you had a Doogle or dashboard accountYour address is confirmed as part of the leak

What Server Admins Should Do

Delete any Double Counter messages posted in your server on October 4 between 12:00 and 16:30 UTC that invite members somewhere else. Then open your audit log and check for permission changes you didn’t make during that window.

Whether to keep the bot is your call. Weigh how much your server relies on alt detection against the fact that every verification stores member IPs with a third party.

What Double Counter Changed After the Breach

Double Counter says it has removed long-lived service-account keys and moved bot tokens and webhooks into a dedicated secret store. Any read of those secrets now gets logged, with alerts on sensitive changes. The team also pulled its cache database off an internet-facing host into a private network and replaced its signing keys, which logged everyone out. An audit of 14 cloud projects found no remaining attacker access.

The team reported the breach to France’s data protection regulator, the CNIL, on October 5 under reference FR2610050000001. That falls inside the 72-hour window GDPR requires. Tellter, the developer behind Double Counter, also filed a criminal complaint.

FAQ

Did the Double Counter breach leak my Discord password?

No. Double Counter never receives Discord passwords because login happens on Discord’s side. The leak covers user IDs, usernames, IP addresses, location and ISP details, browser fingerprint hashes and about 1 million emails. Turn on multi-factor authentication anyway, since phishing emails are the most likely follow-up.

When did the Double Counter data breach happen?

The attacker first probed the old server on October 3, 2026, and got in early on October 4. Data was copied out between 15:09 and 15:34 UTC that day. Double Counter restored service at 19:19 UTC on October 4 and disclosed the breach on October 5.

Can someone find my home address from my leaked IP?

Usually not directly. An IP points to your internet provider and a rough area, often a city or postal code. Combined with your username and other public posts, though, it can narrow things down a lot. If your ISP gives dynamic IPs, restarting your router may get you a new one.

Is Double Counter safe to use now?

Double Counter has rotated all credentials, moved databases off the public internet and removed long-lived cloud keys. Those changes close the holes used in this attack. Whether that’s enough is up to each server owner, since the bot still needs to store member IPs to work.

How many Discord users were affected by Double Counter?

About 28 million Discord accounts had user IDs and usernames exposed. About 27 million had IP and location data exposed, about 25 million had browser fingerprint hashes taken, and roughly 1 million email addresses were included.

- Advertisement -
Divyesh Moghe
Divyesh Moghehttp://www.talkesport.com
Content writer and Esports enthusiast

Popular Articles