The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Double Counter's own incident report (Oct 5), quoted by Insider Gaming, Cybernews, Dexerto and CyberSecurityNews, confirms the Oct 4 breach: ~28M Discord IDs/usernames and ~27M IP/location records partly copied and treated as exposed, ~25M user-agent hashes and ~1M emails copied. Discord told Dexerto it was not a breach of Discord. Have I Been Pwned lists 274,922 addresses from the public dump.

Sourcing
4independent sources

via Insider Gaming

Insider Gaming · track record
57Stories
100%Verified
2730d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Gaming/Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts
VERIFIEDBy Xavier Rivera· ·3 min read

Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts

Discord server-protection bot Double Counter says an October 4 attack exposed IDs and usernames tied to up to 28 million Discord accounts, plus IP and coarse location data for about 27 million and roughly 1 million email addresses. Discord says its own platform was not breached.

Source:Insider Gaming
Post
Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Double Counter, a third-party Discord bot that server owners use to block alt accounts, raids and VPN users, says an October 4 breach exposed data tied to up to 28 million Discord accounts. Discord says its own platform was not breached.

What was exposed, according to Double Counter. In an incident report published October 5, the bot's operator, Tellter, said the attacker copied about 12 GB from one of its databases between 15:09 and 15:34 UTC. Discord IDs and usernames for about 28 million accounts, and IP addresses with coarse geolocation for about 27 million, were partly copied. Because the company cannot tell exactly which of those records left, it treats all of them as exposed, which is why 28 million is an upper bound rather than a confirmed count.
Because the company cannot tell exactly which of those records left, it treats all of them as exposed, which is why 28 million is an upper bound rather than a confirmed count.
User-agent hashes for about 25 million accounts and roughly 1 million email addresses were copied in full. According to the report, the email addresses belong to people who gave one to Double Counter or its Doogle service, such as dashboard users, customers and advertisers. The categories overlap, so the figures should not be added together.

Double Counter says about 15 million VPN detection logs were not copied, a separate cold-storage database was not affected, and it never held Discord passwords. Have I Been Pwned added the breach on October 7 after a dataset with about 275,000 unique email addresses and Discord usernames was posted publicly.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
How the attack happened. The attacker got in through a retired server from Double Counter's old hosting setup that was still running a vulnerable analytics tool, then used credentials stored on it to reach the company's cloud. They were active in its cloud for 5 hours and 51 minutes (12:03 to 17:54 UTC). During that time they took the bot's Discord token and used it to post links to their own server in about 50 large Discord servers.
The categories overlap, so the figures should not be added together.
They also used a stolen payment key to run $7,316 in fraudulent charges on a separate payment account. Double Counter says only three cards were charged, one of its own and two customers', and that the customers were refunded. It says no stored card numbers were exposed and that it revoked every payment-provider key at 17:14. Service was restored at 19:19 UTC with new credentials.

Discord's response. In a statement to Dexerto, Discord said: “While this was not a breach of Discord, we've disabled new installs of the app while we work with Double Counter to understand the full scope of the incident.” Double Counter says it has reported the breach to France's data protection authority, the CNIL, and is pursuing the attackers in France and the United States.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
What users should do. Double Counter says members do not need to change anything on their Discord accounts but should not join servers promoted in unexpected Double Counter messages. Server owners should delete Double Counter messages sent on October 4 between 12:00 and 16:30 UTC that invite people to another server, and check their audit logs for bot actions in that window. Anyone who gave Double Counter or Doogle an email address should watch for phishing.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securitydiscordbreach
More fromInsider Gaming
  • Xbox Forms XP Division to Grow Franchises Into Film and Events

    Tech · 18h
  • PS5 Crunchyroll Anime Hub Launches Spring 2027

    Tech · 22h
  • Netflix Releases Conjuring Interactive Horror Game October 13

    Gaming · 1d
More inGaming
  • Triple-I Initiative October showcase reveals new games and updates

    Gaming · 9h
  • Paramount developing live-action Cyberpunk 2077 movie, per Deadline

    Gaming · 10h
  • GTA VI Adds Podcasts and Six Radio Stations

    Gaming · 16h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Gaming →
  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.

  • Tech· 

    Red Hat OpenShift 4 hit by CVE-2026-93017 with 7.7 CVSS score

    Red Hat OpenShift Container Platform 4 is affected by CVE-2026-93017, a high-severity flaw that lets attackers read every secret in every namespace. The 7.7 CVSS score reflects broad access granted through an unrestricted ClusterRole on the insights-operator-gather service account.