On October 4, 2026, Double Counter, one of the most widely installed security bots on Discord, was hit by a deliberate multi-stage attack that exposed personal data linked to roughly 28 million Discord accounts. The bot’s operator, the French company Tellter SAS, confirmed the breach in a detailed incident report, saying attackers broke in through a retired server that was still online and copied about 12 GB from a production database in roughly 25 minutes.
What makes this breach especially serious is the kind of data involved. Double Counter exists to spot alt accounts, VPNs and raid bots, so it collects exactly the signals that make leaks dangerous: IP addresses, coarse location data and browser fingerprints, alongside Discord usernames and about 1 million email addresses. If you belong to any large Discord community, there is a real chance your data was in that database, even though you never signed up for Double Counter yourself. This article explains what happened, what was exposed and what you should do now.
What Is Double Counter and Why Does This Breach Matter?
Double Counter is a Discord server-protection bot used in more than 600,000 communities since 2020. It verifies new members using device, browser, network and behavior signals, blocking alt accounts, raids, VPNs, proxies and Tor traffic before they can flood a channel. Because it sits inside thousands of the largest Discord servers, its database accumulated profiles on tens of millions of Discord users who had no direct relationship with the bot or its maker.
That reach is precisely why this breach matters beyond Tellter’s own customer list. Discord told the press that its own platform was not breached and that it has disabled new installs of Double Counter while it reviews the scope with the vendor. But the data stolen from the bot’s database did not need Discord to be breached: it was collected legitimately by the bot and stored by Tellter.
Exactly What Data Was Exposed
Tellter compared the roughly 12 GB of data that left its network with the size of each database table to determine what was copied. The company treats all of the following as potentially exposed:
- Discord user IDs and usernames for about 28 million accounts
- IP addresses with coarse geolocation (country, region, city, postal code and ISP) for about 27 million accounts
- User-agent and browser fingerprint hashes for about 25 million accounts
- About 1 million deduplicated email addresses of users who had shared one
A separate public corpus of 274,922 unique email-and-Discord-username pairs has since been loaded into Have I Been Pwned, giving you a way to check whether your email was among them. No Discord passwords were exposed, because Double Counter never handles login credentials: authentication happens entirely on Discord’s side.
How the Attack Unfolded: A Forgotten Server Was the Weak Link
The incident is a textbook case of forgotten infrastructure becoming the entry point. According to Tellter’s forensic timeline, the attacker first probed a retired OVH server from the company’s previous hosting setup on October 3. That server was still running a publicly reachable self-hosted Metabase analytics instance with a known vulnerability, which let the intruder forge an administrator session early on October 4.
From there the attack moved fast. The old server still contained live cloud credentials, so the attacker pivoted into Tellter’s production cloud project and stayed active for 5 hours and 51 minutes. During that window they read the bot’s Discord token from a running container, used it to post invitations to their own server in about 50 large Discord communities (appearing as legitimate Double Counter messages), copied the database, and even found a payment key for a separate Tellter product, Atis, which they used to make $7,316 in fraudulent charges. The small customer charges that resulted were refunded.
Tellter cut off access the same day, found no persistence, replaced all exposed credentials and restored service by 19:19 UTC on October 4. The company disclosed the breach on October 5, notified France’s data protection authority (CNIL) and says it has filed a criminal complaint. The pattern will feel familiar to anyone following recent breach post-mortems: the Warlock ransomware attacks we covered recently also started from one unpatched, overlooked server.
What the Exposure Means for You
For most affected users, the immediate risk is not account takeover but targeted harassment, phishing and doxxing. An IP address tied to your Discord username, your approximate city and your ISP gives a determined harasser a meaningful starting point, especially combined with things you have posted publicly. If your email was in the exposed set, expect more convincing phishing attempts that reference your Discord activity.
The 275,000 email-and-username pairs now searchable in Have I Been Pwned make the phishing risk concrete rather than theoretical. Attackers routinely buy or collect these corpora and feed them into automated phishing campaigns. As with the Revolut breach earlier this month, assume that scammers now have enough context to impersonate support staff and gaming services convincingly.
What to Do Now: 7 Practical Steps
- Check Have I Been Pwned. Enter the email you use for Discord at haveibeenpwned.com and confirm whether it appears in the Double Counter corpus of 274,922 pairs.
- Enable two-factor authentication on Discord. Go to User Settings, My Account, and turn on two-factor authentication. It does not stop someone knowing your IP, but it hardens your account against phishing follow-ups.
- Watch for phishing referencing Discord. Treat any email, DM or message that references your Discord username, a server you belong to, or Double Counter itself with suspicion. Double Counter will never ask you for a password or a login token.
- Reset your router if your ISP uses dynamic IPs. If your internet provider assigns dynamic addresses, restarting your router or modem will usually give you a new IP, shrinking the window where the leaked one is accurate.
- Review bot permissions on servers you moderate. If you run or moderate a Discord community, audit which third-party bots can read and store member data, and whether each one is still necessary.
- Consider a VPN for gaming sessions. Because IPs were the most sensitive data exposed here, routing Discord traffic through a reputable VPN reduces the value of any future leak for swatting or DDoS targeting.
- Stay calm about location. The exposed geolocation is coarse: country, region, city and postal code, not a street address. It becomes dangerous mainly in combination with other public information, so tightening what you share publicly still helps.
Is Double Counter Safe to Use Now?
Tellter says it has rotated all credentials, moved databases off the public internet and removed long-lived cloud keys, closing the holes used in this attack. Those are the right fixes, and the company’s unusually detailed disclosure is a good sign. The honest answer for server owners is a judgment call: the bot still needs to store member IPs and device signals to do its job, so the fundamental trade-off has not changed. If you moderate a community, weigh that against alternatives and against how much you trust a vendor that left a retired server with live credentials online.
There is a broader lesson here that echoes other breaches we have covered, from the Pentagon contractor breach to the enterprise zero-days hitting this year: attackers keep finding their way in through infrastructure everyone forgot about. Retiring a server means actually shutting it down, deleting its credentials everywhere else, and verifying it is unreachable, not just stopping its bills. That is a process failure, not a sophistication problem, and it keeps working for attackers.
Frequently Asked Questions
Did the Double Counter breach leak my Discord password?
No. Double Counter never receives Discord passwords because login happens on Discord’s side. The leak covers user IDs, usernames, IP addresses, location and ISP details, browser fingerprint hashes and about 1 million emails. Enable two-factor authentication anyway, since phishing is the most likely follow-up.
When did the Double Counter data breach happen?
The attacker first probed the old server on October 3, 2026, broke in early on October 4, and copied about 12 GB of database data between 15:09 and 15:34 UTC that day. Tellter restored service at 19:19 UTC on October 4 and disclosed the breach publicly on October 5.
How many Discord users were affected by Double Counter?
About 28 million Discord accounts had user IDs and usernames exposed. Around 27 million had IP and location data exposed, about 25 million had browser fingerprint hashes exposed, and roughly 1 million email addresses were included.
Was Discord itself hacked?
No. Discord says its own platform was not breached. The data was collected by the Double Counter bot and stolen from its operator Tellter’s infrastructure. Discord has disabled new installs of the bot while it reviews the scope with the vendor.
Can someone find my home address from my leaked IP?
Usually not directly. An IP address points to your internet provider and a rough area, often a city or postal code. Combined with your username and public posts, though, it can narrow things down considerably. If your ISP gives you a dynamic IP, restarting your router may get you a new one.
What should I do if my email was in the leak?
Check Have I Been Pwned to confirm, be extra skeptical of emails and DMs that reference your Discord activity, make sure your Discord password is unique and two-factor authentication is on, and consider a password manager plus an email alias for gaming accounts going forward.
