A surveillance app built to keep bad actors out of Discord communities spent nearly six hours letting one in, copying roughly 12 GB of user data before anyone stopped it. Double Counter, an anti-raid and account-verification bot operated by Tellter SAS, suffered what the company described as “a deliberate, multi-stage attack” on October 4, 2026.
If you have ever joined a Discord server that used Double Counter for identity verification, your information may have passed through its systems.
What the Attacker Actually Did
The breach began not with a sophisticated exploit but with a legacy server that should have been secured long before October 4.
The entry point was a Metabase analytics installation sitting exposed on a legacy server: the digital equivalent of a bouncer who leaves the club’s master key under the doormat. The attacker recovered cloud credentials from that system and moved into Double Counter’s wider infrastructure, according to the company’s disclosure.
The access window ran approximately five hours and 51 minutes before containment measures took effect. During that window, the attacker also hijacked Double Counter’s bot token and reportedly posted links to an attacker-controlled server across roughly 50 large Discord communities.
What Was Taken, and What Was Not
The numbers are large, but they require careful reading before you conclude the worst.
Data linked to approximately 28 million Discord IDs and usernames was potentially copied, along with IP addresses and coarse location data (country, region, city, postal code, and ISP) tied to around 27 million accounts. The attacker also copied roughly 1 million unique email addresses and 25 million user-agent hashes, according to reporting by Cybersecurity News and others. Have I Been Pwned published approximately 275,000 email and username records from the stolen material.
Those figures overlap across datasets, so this does not represent 28 million unique individuals who each lost every category of data. Discord passwords were not exposed because Double Counter does not receive or store them. Payment card numbers were held by the payment provider rather than Double Counter and were also unaffected, though a limited number of subscriber records reportedly included names, countries, and postcodes. The company’s cold-storage database, covering approximately 58 million users, was reported unaffected.
Why This Keeps Happening, and What Needs to Change
The Double Counter breach is not an isolated accident; it reflects predictable, structural failures that Discord and its ecosystem partners have the means to fix.
An analytics tool on a legacy server should not carry credentials that reach production cloud environments. That is a well-documented security failure, and it is the kind of gap that routine audits are designed to catch before an attacker finds it first.
The deeper problem is structural. Discord’s ecosystem allows third-party bots to collect persistent identity and network data at a scale many users never consciously review or understand. A verification prompt feels like routine friction, the way a cookie banner does, but passive acceptance is not the same as informed consent , a failure pattern seen in cases of secretly tracking users across other platforms. Discord should require data minimization from integrations, mandate clear user disclosure at every verification checkpoint, and enforce regular third-party security audits rather than waiting for incidents to reveal what its partners are holding.
Tellter SAS notified France’s data-protection authority, CNIL, on October 5 and said it is pursuing legal action. That is the procedurally correct response. It is not, however, a substitute for the proactive standards that would have prevented the breach.
Discord’s Position
Discord drew a clean line between its own platform and the incident, but that line offers little comfort to affected users.
Discord said the incident involved a third-party application and was not a breach of Discord itself, and the company disabled new Double Counter installations while assessing the full scope. That distinction is technically accurate. In practice, data linked to millions of accounts connected through Discord-adjacent verification services was still exposed, regardless of where the intrusion originated.
What You Should Do Now
No passwords were taken, but the data that was exposed is more than enough to fuel a convincing phishing attempt.
Treat any message that references your Discord username, server membership, or location as a potential social-engineering attempt. Turn on multi-factor authentication everywhere it is available. Check your email against a reputable breach-notification service such as Have I Been Pwned rather than any unfamiliar “breach checker” site that surfaces in your feed.
Platforms that profit from community scale owe those communities more than a post-breach press release and a regulatory filing. That obligation starts before the breach, not after.




























