Hackers take over Discord security bot, spam groups, and steal from credit cards
The 6-hour breach affects 28 million accounts.

Image by Cybernews
- Double Counter says a six-hour breach exposed data tied to about 28 million Discord accounts.
- Exposed data included Discord usernames, IP addresses, rough locations, email addresses, and VPN detection records.
- The attacker used a stolen bot token to post spam invites in about 50 large Discord communities.
- Double Counter says no passwords or stored card numbers were exposed, but $7,316 was fraudulently charged.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Double Counter, a verification and anti-alt account service used by Discord communities, confirmed the incident after an attacker spent nearly 6 hours moving through its infrastructure on October 4th.
The attacker managed to exfiltrate a treasure trove of user data while roaming within Double Counter’s system.
What Discord user data was breached?
- Discord user IDs and usernames for around 28 million accounts
- IP addresses and coarse geolocation data for ~27 million accounts, including country, region, city, postal code, and ISP
- User-agent hashes for around 25 million accounts
- ~1 million email addresses
- ~15 million VPN detection records containing IP addresses and user agents
Double Counter stated that Discord passwords were never held by Double Counter and were not exposed. The company said payment card information was not stored in the breached the database.
Double Counter also said a separate cold-storage database containing information on approximately 58 million users was not accessed since it was outside the affected infrastructure. Its behavioral data database was likewise stored elsewhere and confirmed to be unaffected.
The combination of Discord usernames, IP addresses, approximate location, and other identifying signals could be particularly useful to anyone trying to profile or track accounts across online communities.
Over $7K stolen from credit cards
The attacker reportedly exploited their access to put fraudulent charges on credit cards saved in the system.
The attacker made a sequence of escalating charges of $1, $10, $100 and $1,000 against one of Double Counter's own cards.
The total fraudulent activity amounted to $7,316. Two additional charges, totaling $18, were made against 2 customers. Both customers were refunded.
Double Counter says only 3 cards were charged in total and that no stored card numbers were exposed.
Check if your data was exposed
Find out if your email and related personal information have appeared in known data breaches.
How did the attacker breach Double Counter’s system?
According to Double Counter’s account of the incident on their blog, the attacker first broke into an abandoned server. The server was part of the company's previous OVH hosting environment and was no longer connected to its operational service.
The attacker began probing the server from rotating VPN addresses on October 3rd. They exploited a vulnerability in a publicly exposed analytics tool to obtain an administrator’s credentials and then used those credentials to access the company’s cloud infrastructure.
The attacker opened a shell inside a running Double Counter bot container and extracted its Discord token. That token effectively gave them control over the bot's identity on Discord.
Double Counter says the attack has been contained and the service restored.
The security bot started advertising the attacker
After the takeover, the compromised bot posted invitations to the attacker's Discord server in approximately 50 large Discord communities using Double Counter.
The messages appeared to have been sent by Double Counter itself. One of the largest servers targeted was reportedly "Steal a brainrot."
Double Counter says most of the messages have since been removed by the company or server moderators.
“Messages sent with the stolen token went straight to Discord without passing through our systems, so we identified the affected servers from the reports we received and from the bot’s own message history,” Double Counter staff wrote.