Discord protection bot Double Counter hit by breach exposing around 1 million email addresses

Double Counter, a security service that protects Discord servers from raids and unauthorized alt accounts, experienced a significant data breach on October 4 following a “deliberate, multi-stage attack.” Approximately 1 million email addresses were stolen, along with partial exposure of Discord IDs and IP addresses for millions of additional users—with Discord IDs and usernames for around 28 million accounts partially copied.

The attackers exploited a vulnerability in a publicly accessible analytics tool on one of Double Counter’s legacy servers, gaining access to cloud credentials. They maintained access for just under six hours before the vulnerability was closed. While Discord itself was not directly targeted, the breach demonstrates the risks posed by security vulnerabilities in third-party services that integrate with major platforms.

Double Counter provides moderation and anti-raid protection for Discord communities, making this breach particularly significant given the sensitive nature of the data exposed. The incident underscores the security challenges faced by auxiliary services in the gaming ecosystem and highlights the need for robust security practices across cloud infrastructure and legacy systems.

Sources