Double Counter has confirmed a serious security breach affecting its Discord protection service.
>The attack happened on October 4, 2026 and lasted almost 6 hours.
>Attackers exploited a vulnerability in Metabase, an analytics tool running on an old server.
>They gained access to Double Counter’s cloud infrastructure and stole the Discord bot token.
>The compromised bot was used to post the attackers’ own Discord links across around 50 large servers.
>About 12 GB of database data was copied during the attack.
>Attackers also used a stolen payment key to make $7,316 in fraudulent charges. Double Counter says customer funds were safe.
>Double Counter says the exposed data included information from its databases, and the company is still investigating exactly what was accessed.
If you’ve used Double Counter, it’s worth taking the breach seriously, especially because the service collects Discord account and technical information for its verification system.
A new data breach involving Double Counter has exposed information connected to Discord users affecting around 275,000 unique email addresses.
According to Have I Been Pwned, the exposed data includes:
-Email addresses
-Discord usernames
-Names
-Geographic information
-Country and postcode for some paying subscribers
The breach was linked to a vulnerability in Metabase, the analytics platform used by Double Counter.
If you’ve used Double Counter on Discord, check whether your email was affected and stay alert for phishing attempts or suspicious Discord messages.