Medium

Double Counter Breach: 274K Emails & Discord Usernames Leaked

By Yazoul AI · automated

In October 2026, the Discord server protection service Double Counter suffered a data breach attributed to a vulnerability in the Metabase analytics tool . In its disclosure notice, Double Counter advised that attackers gained access to a subset of its data. A corpus of data was subsequently publish...

Overview

Double Counter, a service that verifies and blocks bot accounts on Discord servers, confirmed a data breach in October 2026 that exposed 274,922 accounts. The leak stemmed from a vulnerability in Metabase, an analytics dashboard the company used internally. Attackers reached a subset of Double Counter’s data, and a corpus was later published publicly containing 275,000 unique email addresses and Discord usernames. The incident has been logged with Have I Been Pwned, making it searchable for anyone who wants to verify exposure.

What Was Exposed

The bulk of the leaked records center on three data types:

  • Email addresses and usernames: These are the account identifiers attackers use to build phishing lists and credential-stuffing targets.
  • Names: Combined with the above, names help attackers personalize scams and cross-reference leaked data from other breaches.
  • A small set of subscriber records: Purchases processed through Stripe were present for a limited number of paying users, including names, countries, and postcodes.

No passwords, payment card numbers, or government IDs appear in the published corpus, which keeps the severity at medium rather than critical.

Why This Leak Still Matters

A leak of “just” emails and usernames is easy to underestimate. Double Counter’s user base skews toward Discord server owners, moderators, and community managers - people who often reuse the same contact details across Discord, GitHub, Patreon, and their own projects. Attackers who know a username and email pairing can craft convincing Discord DMs, password-reset phishing, or targeted social-engineering attempts against server staff. The subscriber records compound this: country and postcode data give scammers enough locality detail to make impersonation feel legitimate.

How the Breach Happened

The exposure points to a third-party analytics tool, not Double Counter’s core Discord integration. Metabase dashboards are frequently misconfigured or left without adequate authentication, which turns an internal reporting tool into an open door. Because the company disclosed only that attackers “gained access to a subset of its data,” the exact root cause - an unpatched instance, weak credentials, or an exposed query endpoint - has not been fully detailed publicly. What is clear is that sensitive customer records sat inside analytics infrastructure that became reachable from outside.

What to Do Right Now

  • Check your exposure: Search your email at haveibeenpwned.com or go directly to the Double Counter breach page on HIBP to see if your address appears.
  • Rotate reused passwords: Even though passwords were not leaked here, any account sharing the same email should have a unique password. Use a password manager.
  • Watch for phishing: Treat unexpected Discord DMs, emails, or “account verification” links referencing Double Counter as suspect. The leaked data makes these outreach attempts more credible.
  • Lock down Discord: Enable two-factor authentication on your Discord account and any servers you administer, and review which bots have administrative permissions.
  • If you were a paying subscriber: Be alert for scams referencing your country or postcode. Stripe itself was not breached, so verify any payment notice directly through Stripe or your bank.

Security Insight

The defining risk in this breach is supply chain, not the Discord-facing product. Double Counter’s customers trusted a bot to guard their servers, yet the leak originated in an internal analytics layer that most users never knew existed. This mirrors a recurring pattern across SaaS platforms: companies harden the customer-facing application while leaving business-intelligence tools with default configurations and broad data access. The lesson for every vendor handling user data is that your attack surface is only as small as your least-governed internal tool.

Further Reading

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.