Published: October 8, 2026 · Last updated: October 8, 2026
TL;DR: Double Counter, a widely used Discord server-security bot, got breached on October 4 through an old analytics tool nobody had bothered to shut down. Have I Been Pwned has confirmed at least 275,000 real email addresses and usernames in the leak, and the attacker claims the broader exposure touches account metadata for close to 28 million users.

There is a special kind of irony in a security bot getting hacked, and that is exactly what happened to Double Counter, a bot that thousands of Discord server owners install specifically to catch raids, spam, and malicious bots before they cause damage.
According to breach-tracking accounts and multiple cybersecurity outlets, including CyberSecurityNews and GBHackers, an attacker got into Double Counter’s cloud environment on October 4 through a Metabase analytics instance that had been retired but, crucially, was never actually taken offline. That is the part worth sitting with. The vulnerability was not some novel zero-day. It was a dashboard someone forgot to decommission, still reachable from the open internet, still connected to live databases.
Have I Been Pwned has already added the breach to its database, confirming 275,000 email addresses and usernames published online, a number corroborated separately by PC Guide, GameRiv, and Softonic. That figure includes paying subscribers of the bot’s premium tier, which is its own kind of insult: people paid for a security product and got their account details leaked as a result of using it.
The attacker’s own claims go much further than the confirmed email count. Posts attributed to the breach, circulated by threat-intelligence accounts tracking the incident, describe roughly 12 gigabytes of stolen data and put the number of Discord accounts with exposed metadata, largely IP addresses tied to server activity, at close to 28 million. That figure has not been independently verified the way the 275,000 email count has, and attacker-supplied numbers in breach disclosures are notoriously prone to exaggeration. Treat the smaller, HIBP-confirmed figure as the hard floor and the larger one as an unverified ceiling until Double Counter or Discord itself publishes a fuller accounting.
Discord has not pulled Double Counter from its bot directory as of this writing, and it is worth being clear that this is a breach of a third-party bot’s infrastructure, not of Discord’s own core platform. That distinction matters for anyone trying to figure out what to actually do about it, but it will not feel like much comfort to server owners who installed Double Counter specifically because they were worried about security in the first place.
If you run a Discord server using Double Counter, or you are a member of one that does, the standard breach playbook applies: change your password if you reused it anywhere else, watch for phishing attempts that reference your server activity specifically, and do not assume a bot marketed as a security tool is automatically more trustworthy than any other third-party integration you have granted access to your account.
Related: Chrome just patched its seventh actively exploited zero-day of the year, and CrowdStrike’s recent South Korea bank hack writeup is a reminder that old, forgotten infrastructure keeps being the easiest way in.
Bottom Line: The confirmed number here is 275,000 people, not 28 million, until someone proves otherwise. But the root cause, a retired tool nobody bothered to actually shut down, is painfully common and worth an audit of your own stack today, not after you read about your own breach somewhere else.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest



