The Discord "security" bot hack is much worse than you think.
Double Counter is a "security" bot that tracks alt accounts, users circumventing server bans, and stops server raids. It is not directly associated with Discord, run by Tellter SAS, but is a widely used bot on many Discord servers.
Here is what the company claims is exposed...
>Discord user IDs and usernames of about 28 million accounts
>IP addresses, along with coarse geolocation from 27 million accounts that includes data such as country, region, city, postal code, and ISP info
>User agent hashes, which include browser user data, city, and country info from 25 million accounts.
>Email addresses from 1 million accounts are exposed... 840k from Doogle (Double counter affiliated addresses) and 240k from the dashboard.
So far, only 275k emails, usernames, and other info have been found in the public dump according to "Have I Been Pwned". Likely what's happening is that the hackers are holding back or are actively selling additional data, not the full totality of the data that was stolen.
Based on other leaked info, it sounds like a much larger portion of their database was stolen because of shared credentials across multiple levels at the company. Untouched "Cold storage" data is the company's claim and has not been verified.
If you ever clicked on a double counter verification link, your Discord ID, along with a lot of other information, is now likely exposed or will be exposed.
The bot can also run in background screening mode that will scrape your limited user data, and in those cases you are also likely exposed, but with less information.
Discord allowed this, and the bot is still on their app list. What Discord needs to do is ban any kind of app or bot that erodes privacy under the guise of "ban evasion" and reducing server raids... because 3rd-party companies cannot be trusted with private user information.