A breach at Double Counter, a third-party Discord verification and server-protection service, exposed data associated with its users and was followed by malicious invite messages posted through the compromised bot. The incident was in Double Counter’s infrastructure; the available evidence does not indicate that Discord’s own systems were breached.

What happened

Double Counter says an attacker accessed a retired server in its former hosting environment on October 4, 2026, exploited an exposed analytics tool, and obtained credentials that led into its cloud infrastructure. The attacker also took the bot token and used it to post invitations to an attacker-controlled server in about 50 Discord communities. The company says it contained the incident and restored the service that day.

What data may be involved

Double Counter’s incident report and independent reporting describe copied Discord IDs and usernames, IP addresses with approximate location information, and email addresses. Cybernews reports the company estimated these records were associated with roughly 28 million Discord accounts, including IP/location records for about 27 million and around one million email addresses. These are vendor-reported record estimates, not a confirmed count of unique people.

Have I Been Pwned says a publicly circulating dataset added on October 7 contained about 275,000 unique email addresses and Discord usernames. That smaller figure describes the corpus HIBP reviewed; it is not the same measure as Double Counter’s broader estimates.

Double Counter says it did not hold Discord passwords and that stored card numbers were not exposed. Cybernews reports fraudulent charges were made during the incident, while the company said no card numbers from the affected database were exposed. Treat password and payment details as claims about the operator’s affected systems—not as evidence of a Discord password leak.

What users and server admins should do

If you used Double Counter, check whether your email appears in Have I Been Pwned’s Double Counter entry. Be alert for targeted phishing that references your Discord name, email, or server activity. Don’t follow unexpected verification links or invitations, and never enter your Discord password or 2FA code after following a message from a bot.

Double Counter says ordinary members do not need to change Discord account settings solely because of this incident. Be alert for phishing, especially if you used the service or find your email in the published breach corpus.

If you administer a server that used the bot, Double Counter advises removing its messages sent on October 4 between 12:00 and 16:30 UTC that invite members to another server, and reviewing the server audit log for actions attributed to Double Counter during that window.

Why the distinction matters

Double Counter is an independent service used by Discord communities, not a Discord-owned account system. The breach shows how a third-party verification flow can collect and expose information linked to Discord identities. It does not, by itself, show that Discord login credentials or Discord’s core platform were compromised. Discord’s status page currently reports its systems operational; that status is separate from this third-party incident.

Sources

Double Counter: Security Incident Report — 4 October 2026

Have I Been Pwned: Double Counter breach entry

GamesIndustry.biz: Double Counter breach exposed Discord-linked data

Cybernews: Discord user data breach hits 28 million accounts

Discord Status API summary