Discord server protection service Double Counter has suffered a major security breach after attackers exploited a vulnerability in the Metabase analytics tool running on an old server.
The incident exposed a significant amount of user data, while a publicly released portion of the information includes nearly 275,000 email addresses and Discord usernames.
Double Counter said the attack took place on October 4, 2026, and involved a retired server from its previous hosting infrastructure. According to the company’s incident report, attackers gained access through a publicly reachable self-hosted Metabase installation and used the compromised server to obtain legitimate credentials that provided access to parts of Double Counter’s cloud infrastructure.
The attackers subsequently accessed the Double Counter environment, obtained the Discord bot’s token and posted links to their own Discord server through the bot in about 50 large Discord communities. Double Counter said the attackers also copied part of one of its databases, with approximately 12GB of data transferred during the incident. The company eventually terminated the attackers’ access and restored the service with new credentials.
The amount of data potentially exposed is considerably larger than the 275,000 email addresses initially highlighted in reports about the breach. Double Counter says approximately 28 million Discord user IDs and usernames were in the affected data, with the copied portion treated as exposed. Around 27 million accounts had IP address and coarse geolocation information, including country, region, city, postal code and ISP data. The company also said approximately 25 million user-agent hashes were copied.
Email data was also affected. Double Counter estimates that around 1 million email records across its services and customer contacts were copied. The company says this included approximately 840,000 Doogle accounts and around 240,000 contacts connected to the Double Counter dashboard, server management, customers and advertisers.
Have I Been Pwned has separately added the Double Counter breach to its database. Its current listing shows approximately 274,900 affected email addresses, with the breach added on October 7, 2026. HIBP lists email addresses, geographic locations, names and usernames among the compromised data.
New breach: Discord server protection service Double Counter suffered a breach earlier this week due to a Metabase vulnerability. The data included 275k unique email addresses and Discord usernames. 25% were already in @haveibeenpwned. Read more: https://t.co/f6oQ56QaIW
— Have I Been Pwned (@haveibeenpwned) October 7, 2026
A small number of paying subscribers were also affected, with some records containing names, countries and postcodes. However, Double Counter said Discord passwords were never collected by the service and stored payment card details were not present in the affected database.
The incident also involved a separate payment account belonging to another Tellter product. Double Counter said attackers used a stolen payment-provider key to make fraudulent charges totaling $7,316, including two small charges to customers. The company said those customer charges were refunded and that the payment account used for Double Counter subscriptions was not affected.
Double Counter says it has shut down the compromised legacy server, revoked exposed credentials, reset the Discord bot token, removed exposed webhooks, moved databases away from public access and rotated sensitive keys. The company also said it audited its cloud infrastructure and found no remaining backdoor left by the attackers.
For Discord users, Double Counter recommends avoiding unexpected server invitations sent through the bot and checking for suspicious messages. The company specifically advised server administrators to review their Discord audit logs and delete unexpected invitations sent by Double Counter during the attack window.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Users whose email addresses were included in the breach should also be alert for phishing messages. Have I Been Pwned currently provides a way to check whether an email address appears in the Double Counter breach.



