A Discord server-protection bot called Double Counter suffered a breach on October 4, 2026, exposing roughly 1 million full email addresses and touching data tied to an estimated 28 million Discord accounts, according to GamesIndustry.biz and CyberSecurityNews. The company behind the bot, identified in reporting as Tellter, called it a “deliberate, multi-stage attack” and says service was restored within hours. Discord, for its part, says its own platform was not breached.
The incident lands in a familiar spot for anyone who follows Discord’s third-party app ecosystem: a widely trusted add-on, built to protect communities from raids and alt-account spam, turns out to be the weak link. Double Counter runs on thousands of servers that rely on it to catch fake accounts before they flood a channel. That reach is exactly why the breach matters well beyond Tellter’s own customer list.
What happened on October 4
According to the reporting, attackers broke into a legacy server running a publicly accessible analytics tool, then used that foothold to obtain cloud credentials. From there they moved into Double Counter’s broader infrastructure and copied roughly 12 GB of data, per CyberSecurityNews. Double Counter has not disclosed the specific analytics software involved, and the company’s public statement focused on scope and response rather than the technical root cause.
Legacy infrastructure left exposed to the public internet is a recurring theme in breach post-mortems this year. The EY data breach traced back to a hack that ran undetected for 15 days before anyone noticed, and the pattern of an old, forgotten system becoming the entry point keeps showing up across industries that have nothing else in common with each other.
How attackers got from a dashboard bug to a Discord token
Once inside, the attackers reportedly escalated beyond data theft. They obtained Double Counter’s own Discord bot token and used it to post links in roughly 50 large Discord servers, according to CyberSecurityNews. A hijacked bot token is a particularly ugly outcome in this kind of breach: thousands of server admins trust the bot’s identity, so a malicious link posted under that account carries more credibility than a cold-DM phishing attempt would.
Reports also say the attackers used a stolen payment key to commit financial fraud against a separate account. Tellter has not detailed the amount or the account involved, and that piece of the incident remains one of the least-documented parts of the story so far.
The numbers: what was actually exposed
The headline figures from this breach are large, but they don’t all describe the same thing, and treating them as additive overstates the damage. Data tied to an estimated 28 million Discord accounts, including Discord IDs and usernames, was treated as exposed. IP addresses and coarse location data connected to roughly 27 million accounts fell into the same bucket. Separately, around 25 million user-agent hashes were reportedly copied.
The more sensitive subset is the roughly 1 million email addresses copied in full. CyberSecurityNews broke that figure down further: about 840,000 addresses tied to Doogle accounts, and about 240,000 tied to the Double Counter dashboard itself, including server-management contacts, customers, and advertisers. A separate, publicly posted dataset contained around 275,000 unique email addresses paired with Discord usernames, a set that reporting says overlaps with the larger pool rather than adding to it.
Breach exposure by data category
| Data category | Approximate scale | Status |
|---|---|---|
| Discord IDs and usernames | ~28 million accounts | Treated as exposed |
| IP addresses and coarse location | ~27 million accounts | Treated as exposed |
| User-agent hashes | ~25 million | Copied |
| Email addresses (full) | ~1 million | Copied in full |
| – of which, Doogle-linked accounts | ~840,000 | Subset of email total |
| – of which, dashboard/customer/advertiser contacts | ~240,000 | Subset of email total |
| Separate public dataset (emails + usernames) | ~275,000 unique | Overlaps with totals above |
| Total data volume copied | ~12 GB | Per reporting |
Why the overlapping datasets make a single victim count impossible
Reporting on this breach is careful to flag that the datasets overlap, and that adding 28 million, 27 million, and 1 million together to get a combined victim count is the wrong math. A single Discord account can appear in the Discord-ID set, the IP-address set, and the email set all at once. The real number of individual people affected remains unconfirmed, and so does the question of whether every record tied to those 28 million accounts was actually pulled out of Double Counter’s systems or just exposed to the access the attackers gained.
That distinction matters for anyone trying to size up the incident against other recent breaches. The breach of Denmark’s CPR registry affected a cleanly defined 8.8 million people because it drew from a single national database. Double Counter’s figures span several overlapping pools collected from different parts of its stack, which is a messier and, frankly, more common shape for a breach disclosure to take.
Discord’s response: “not a breach of Discord”
Discord moved to draw a clear line between its own platform and the third-party app. In a statement, the company said: “We’re aware of a security incident involving Double Counter, a third-party app available on Discord.” Discord added: “While this was not a breach of Discord, we’ve disabled new installs of the app while we work with Double Counter to understand the full scope of the incident, and we’ll take further action as appropriate.”
Blocking new installs stops the bleeding for servers that haven’t added Double Counter yet, but it does nothing for the servers that already run it, which is most of the user base that matters here. Discord’s own safety page lays out its general approach to third-party app review, though the platform has limited visibility into what a bot does with data once a server owner grants it access.
Tellter’s recovery timeline and the CNIL notification
Double Counter says it disabled the stolen credentials, rotated its secrets, and moved its databases onto private networks, restoring service at 19:19 UTC on October 4, 2026, the same day the attack began. That’s a same-day recovery, which is fast by the standard of most breach timelines, though speed of recovery says nothing about the data that already left the building.
On October 5, Double Counter notified France’s data-protection authority, the CNIL. A next-day notification to a European regulator puts Double Counter in noticeably better shape than some recent breach disclosures. The ASOS breach turned into a dispute over when the GDPR’s 72-hour notification clock even started, and the EY breach carried an 81-day gap between the hack and the eventual notice. Whether a one-day gap satisfies GDPR’s strict requirements for every jurisdiction where affected users live is a separate question regulators will have to work through.
How Double Counter compares to recent Discord-adjacent incidents
| Incident | Entry point | Scale | Notification gap |
|---|---|---|---|
| Double Counter (Oct. 2026) | Legacy analytics tool + stolen cloud credentials | ~1M emails in full, data tied to 28M accounts | 1 day to CNIL |
| Brevo supply-chain hack | ClickFix social engineering | ~100,000 sites affected | Not publicly detailed |
| ASOS breach claim | Disputed; Snowflake denied involvement | Scope disputed | GDPR clock start disputed |
| EY data breach | Undetected intrusion | Undisclosed record count | 81 days |
| Denmark CPR breach | National registry exposure | 8.8 million people | Not publicly detailed |
Set against that table, Double Counter’s response timeline looks disciplined even as the exposure numbers look large. The company that comes out looking worst in a side-by-side isn’t necessarily the one with the biggest breach. It’s the one that took the longest to say anything.
Historical context: third-party Discord apps keep becoming the target
Discord’s bot and app ecosystem has grown into one of the platform’s defining features, and also one of its biggest blind spots. Server owners install moderation bots, leveling bots, music bots, and anti-raid tools like Double Counter with a few clicks, often granting broad permissions without reading through what each bot actually does with the data it collects. Discord reviews apps before they’re listed, but that review process can’t catch a vulnerability introduced months later in a bot operator’s own backend, which is exactly what reporting suggests happened here with a legacy analytics tool.
The Brevo supply-chain hack offers a useful parallel from outside the gaming world: a trusted vendor gets compromised, and the blast radius extends to every customer who plugged that vendor into their own systems. Anti-raid and moderation bots occupy a similar trust position inside Discord servers. A compromised bot account doesn’t just leak data, it can post convincingly inside a community that has learned to trust it.
Discord bot breaches rarely make headlines the way breaches at banks or hospitals do, largely because the data involved, usernames and server activity, reads as low-stakes next to medical records or financial details. That framing is starting to crack. A Discord ID tied to a real email address and a pattern of server activity is enough to build a working profile of a person, and once a bot token is hijacked, the attacker inherits a layer of community trust that took the bot operator years to build and can be spent in minutes.
Market impact on the server-protection bot ecosystem
Anti-raid and anti-alt bots occupy a crowded but thin market. Most operate as side projects or small teams monetizing through premium tiers and server-boost perks rather than venture-backed budgets, which limits how much security infrastructure they can reasonably run. Double Counter’s breach is likely to push server admins to ask harder questions before installing the next anti-raid bot: who operates it, what data it stores, and how long it keeps logs it doesn’t need.
That gap between ambition and resourcing is the real story underneath the breach. A bot that watches every new member across thousands of servers ends up holding a dataset that looks a lot like a mid-size advertising platform’s, Discord IDs, join timestamps, coarse location signals, and now a slice of real email addresses tied to a dashboard product. Few small teams budget for the kind of access logging, network segmentation, and credential rotation that a dataset of that size actually warrants. Tellter’s own after-the-fact response, moving databases onto private networks and rotating secrets, describes security hygiene that arguably should have been in place before the attack, not after it.
Expect scrutiny to fall hardest on bots that, like Double Counter, sit in a privileged position watching every member who joins a server. That data, usernames, IDs, join patterns, and sometimes IP-adjacent signals used to catch alt accounts, is valuable precisely because it’s comprehensive within a narrow slice of a user’s online identity. A bot built to catch fraud is now, ironically, the subject of a fraud-adjacent breach of its own.
Competitive landscape: what server admins use instead
Server owners weighing whether to drop Double Counter don’t have many large, independently audited alternatives to switch to overnight. The anti-raid bot space skews toward smaller, specialized tools rather than a dominant incumbent, which cuts both ways: less concentration risk if one tool fails, but also less resourcing behind any single option’s security posture. Admins moving away from Double Counter in the short term are more likely to fall back on built-in Discord moderation settings, such as verification-level gates and join-rate limits, rather than a like-for-like bot replacement.
That shift, even if temporary, matters for the broader bot economy. Every server that disables a third-party anti-raid tool in favor of native Discord settings is a data point the platform itself will likely cite the next time it reviews how much access third-party apps should get by default.
GDPR enforcement and the regulatory stakes
Tellter operates in France, which puts the CNIL in the driver’s seat for enforcement, but the exposed email addresses almost certainly belong to users well outside French borders. That cross-border reality is becoming the norm rather than the exception. Regulators have increasingly pushed back on companies that treat a single-country notification as sufficient when a breach’s victims are scattered globally, and the pattern of regulators demanding broader disclosure after breaches with international footprints has only hardened this year.
A one-day gap between discovery and CNIL notification is fast on paper. Whether it covers every disclosure obligation Tellter owes to users in other jurisdictions is likely to be the next question regulators ask, not whether the company moved quickly.
Predictions: what happens next
- Expect Discord to publish a follow-up statement once its own review of Double Counter’s scope wraps up, likely within one to two weeks, given the platform already paused new installs.
- The claimed 275,000-email public dataset will probably circulate on breach-notification trackers like Have I Been Pwned in the coming days, giving affected users a way to check exposure directly.
- Other anti-raid and moderation bot operators are likely to announce security audits or credential rotations over the next month, whether or not they were affected, purely to get ahead of admin questions.
- The CNIL’s review will take months rather than weeks, and any fine, if one comes, probably won’t land before mid-2027 given how these cases typically move.
- Server admins should expect at least one more wave of phishing attempts that spoof Double Counter’s branding, since the attackers already demonstrated they can post convincingly using the bot’s own hijacked identity.
What Discord server admins and users should do now
If your server runs Double Counter, treat any links the bot has posted since October 4 as suspicious until Tellter confirms its systems are fully clean. Rotate any shared credentials or webhooks tied to the bot’s dashboard, and warn members not to click links claiming to come from server-protection tools over the past few days.
Individual users whose email addresses may be in the exposed dataset should watch for phishing attempts referencing Discord, Doogle, or Double Counter by name, and should enable two-factor authentication on their Discord accounts if they haven’t already. None of the exposed data, as reported, includes passwords, but email addresses paired with usernames are more than enough to fuel targeted phishing campaigns.
Frequently asked questions
What is Double Counter?
Double Counter is a Discord server-protection bot used by community admins to combat raids and detect alternate accounts.
Who operates Double Counter?
Reporting identifies a company called Tellter as the operator behind Double Counter.
Was Discord itself breached?
No. Discord says the incident involved a third-party app, not its own platform, and has disabled new installs of Double Counter while the investigation continues.
How many people were affected by the Double Counter breach?
The exact number of individual people is unconfirmed because the reported datasets, which range from 28 million accounts touched down to 1 million emails copied in full, overlap with each other and shouldn’t be added together.
Were passwords exposed?
Reporting on the breach does not list passwords among the exposed data categories. Exposed data reportedly includes Discord IDs, usernames, IP and coarse location data, user-agent hashes, and roughly 1 million full email addresses.
Has Double Counter notified regulators?
Yes. The company notified France’s CNIL on October 5, 2026, one day after the attack.
What should server admins using Double Counter do now?
Treat recent links posted by the bot with caution, rotate any connected credentials, and watch for official updates from Tellter confirming the scope of the incident is fully contained.
Is this related to other recent Discord bot or data breach stories?
It’s a separate incident, but it fits a broader pattern this year of attackers targeting trusted third-party tools and legacy infrastructure rather than hardened primary platforms, a pattern also visible in the ShinyHunters FBI breach claim and the DC Medicaid data exposure.




