Discord Bot Double Counter Breach Exposes Data From 28M Users

by Ali Haider

Discord users have been affected by a data breach at Double Counter, a popular Discord verification bot, with information linked to approximately 28 million accounts treated as exposed.

Double Counter disclosed the incident on October 5, saying its infrastructure was targeted in a deliberate attack on October 4. The attacker reportedly gained access through a vulnerability in an analytics tool running on an old hosting server, then used credentials found there to reach the company’s cloud infrastructure.

According to Double Counter, the attacker remained active in its cloud infrastructure for 5 hours and 51 minutes, from 12:03 to 17:54 UTC. During that period, around 12 GB of data was copied from one database between 15:09 and 15:34.

The exposed information includes Discord user IDs and usernames linked to approximately 28 million accounts. IP addresses and coarse location information, including country, region, city, postal code and ISP, were also affected for approximately 27 million accounts.

Around 25 million accounts had user-agent hashes copied. Double Counter uses these hashes, which are generated from browser user-agent information along with city and country data, for alternative account detection.

Email addresses were also copied. Double Counter estimates that information from roughly 1 million accounts was affected, including approximately 840,000 Doogle accounts and around 240,000 addresses associated with its dashboard, server management, customer and advertiser contacts.

Other data was not affected. Double Counter said its VPN detection logs, behavioural fingerprint database and separate cold-storage database were not accessed. The company also confirmed that Discord passwords were not exposed because Double Counter never receives them, while stored payment card information is held by its payment provider.

The attacker also gained control of Double Counter’s Discord bot token and used it to post links to an attacker-controlled Discord server across around 50 large servers. The company also reported approximately $7,316 in fraudulent charges involving a separate payment account, while saying customer funds were safe.

Double Counter said it cut off the attacker’s access, replaced exposed credentials and restored the service at 19:19 UTC on October 4. The company said a full audit found no remaining backdoor and that its infrastructure is now under continuous monitoring.

The company has treated the affected data as exposed because it cannot determine exactly which records were copied from some partially transferred tables. Users should therefore assume that usernames, Discord IDs, IP addresses and other information listed in the disclosure may have been compromised.

You may also like