Breach of Discord verification bot Double Counter exposes data tied to 28 million accounts

· CyberSecurity

TLDR

  • Double Counter, a third-party bot that French company Tellter SAS runs to verify and screen new members on Discord servers, was breached on 4 October, exposing data tied to roughly 28 million Discord accounts.12
  • The attacker got in through an abandoned OVH server still running an internet-exposed Metabase analytics instance, used a forged administrator session to reach Double Counter's cloud infrastructure, then extracted a live bot's Discord token.12
  • Tellter says Discord passwords and stored card numbers were never exposed, but a stolen Stripe key let the attacker rack up $7,316 in fraudulent charges against a company card plus small charges against two customers, since refunded.12
  • Have I Been Pwned separately catalogued 274,922 unique email addresses from a subset of the stolen data that was later posted publicly, a smaller figure than Tellter's own count of about 1 million deduplicated emails taken in the breach itself.3

Discord itself was not breached; the compromised systems belong to Tellter, which markets Double Counter as protecting more than 600,000 communities and 3.7 million monthly users.3 According to Tellter's own incident report, the attacker began probing the retired OVH server from rotating VPN addresses on 3 October, exploited a vulnerability in the exposed Metabase instance to obtain administrator credentials, and used them to reach the company's cloud environment.12 The intruder remained active for roughly five hours and 51 minutes, from 12:03 to 17:54 UTC on 4 October, during which they opened a shell inside a running bot container, extracted its Discord token, granted their own account administrator privileges on Double Counter's support server, reversed a staff-issued ban, and used the bot's identity to post invites to their own server across about 50 large Discord communities.2

Tellter's report lists roughly 28 million Discord user IDs and usernames, about 27 million IP-address and coarse-location records (country, region, city, postal code, ISP), around 25 million one-way browser user-agent hashes, and about 1 million deduplicated email addresses as copied; a separate cold-storage database covering roughly 58 million users, plus its behavioural-data store, sat on different infrastructure and were not accessed.12 Of the exposed emails, GBHackers reports roughly 840,000 belong to Doogle, a sister lookup tool for moderators, with the remainder tied to dashboard users, server managers, customers and advertiser contacts.23 Have I Been Pwned added the breach to its database on 7 October counting 274,922 unique email addresses, a figure describing only the slice of stolen data that was later posted publicly rather than everything Tellter says was copied.3

Containment was not immediate: when responders first rotated the compromised bot's token, the attacker obtained the replacement within two minutes and changed the database administrator password before defenders terminated the session at 15:34 UTC and revoked the underlying service account key.2 A stolen Stripe key tied to a separate Tellter product, Atis, was used to make escalating test charges of $1, $10, $100 and $1,000 against one of Double Counter's own cards, totalling $7,316 in fraudulent activity, plus $18 across two customer cards that have since been refunded.12 Tellter says the attack has been contained, service has been restored, and an audit of 14 cloud projects found no remaining trace of the attacker.12

Why it matters: none of the exposed data came from a Discord system, yet it is still Discord user data, showing how the verification and anti-alt bots that moderators widely install to protect their servers can themselves become a single point of failure exposing tens of millions of accounts at once.

Sources

  1. Discord user data breach hits 28 million accounts (Cybernews)
  2. Discord Security Bot Double Counter Hacked, Exposing Data of Millions of Users (GBHackers)
  3. Double Counter Discord Bot Breach Leaks 275,000 Emails, and the Operator's Own Count Is Higher (Digital Citizen)